Using XACML for privacy control in SAML-based identity federations

  • Authors:
  • Wolfgang Hommel

  • Affiliations:
  • Munich Network Management Team, Leibniz Computing Center, Munich

  • Venue:
  • CMS'05 Proceedings of the 9th IFIP TC-6 TC-11 international conference on Communications and Multimedia Security
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

With Federated Identity Management (FIM) protocols, service providers can request user attributes, such as the billing address, from the user's identity provider. Access to this information is managed using so-called Attribute Release Policies (ARPs). In this paper, we first analyze various shortcomings of existing ARP implementations; then, we demonstrate that the eXtensible Access Control Markup Language (XACML) is very suitable for the task. We present an architecture for the integration of XACML ARPs into SAML-based identity providers and specify the policy evaluation workflows. We also introduce our implementation and its integration into the Shibboleth architecture.