Authentication and authorisation infrastructures in b2c e-commerce

  • Authors:
  • Christian Schlaeger;Guenther Pernul

  • Affiliations:
  • University of Regensburg, Regensburg, Germany;University of Regensburg, Regensburg, Germany

  • Venue:
  • EC-Web'05 Proceedings of the 6th international conference on E-Commerce and Web Technologies
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

One of the reasons for the failure of PKI in b2c e-commerce might be that too much effort was put in entity authentication. In many applications it is not necessary to know who an entity actually is, but to be sure that he/she possesses the proper rights to perform the desired action. This is exactly the purpose of Authentication and Authorisation Infrastructures (AAIs). Today several proposals and running AAIs are available focusing on different aspects. The purpose of this paper is firstly to introduce common representatives and to discuss their focus, secondly to develop criteria and requirements that any AAI for b2c e-commerce has to fulfil and finally evaluate the proposals against the developed criteria. Candidates for evaluation are Kerberos, SESAME, PERMIS, AKENTI, Microsoft Passport, Shibboleth and the Liberty Framework.