Consistency of user attribute in federated systems

  • Authors:
  • Quan Pham;Adrian McCullagh;Ed Dawson

  • Affiliations:
  • Information Security Institute, Queensland University of Technology, QLD, Australia;Information Security Institute, Queensland University of Technology, QLD, Australia;Information Security Institute, Queensland University of Technology, QLD, Australia

  • Venue:
  • TrustBus'07 Proceedings of the 4th international conference on Trust, Privacy and Security in Digital Business
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

In a federated system, it is not uncommon for a user profile registered to a particular system to contain enough attributes to request services from that system. Other attributes may be missing from that profile when services are requested from another system. The problem is that currently, when a change in user attributes happens, it is very difficult for the federation to incorporate the changes in order to resolve the conflict of attributes and maintain the consistency of attributes of users between different systems. Currently ready-for-deploy systems such as Liberty Alliance, Microsoft Windows CardSpace (formerly InfoCard) and Shibboleth do not address this issue efficiently. In general, consistency issues of user attributes in federated system via a 2-dimentional view: consistency between member systems (horizontal consistency) and consistency between federation and local system (vertical consistency). In this paper, we discuss the issue of horizontal consistency to achieve better interoperability and fine-granularity for access control decisions in a federated system by analysing the two approaches to achieve the consistency of user attributes: attribute synchronisation and delegation.