Privacy in browser-based attribute exchange

  • Authors:
  • Birgit Pfitzmann;Michael Waidner

  • Affiliations:
  • IBM Zurich Research Lab, Rüschlikon, Switzerland;IBM Zurich Research Lab, Rüschlikon, Switzerland

  • Venue:
  • Proceedings of the 2002 ACM workshop on Privacy in the Electronic Society
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Browser-based attribute-exchange protocols enable users of normal web browsers to conveniently send attributes, such as authentication or demographic data, to web sites. Such protocols might become very common and almost mandatory in general consumer scenarios over the next few years. We derive the privacy requirements on such protocols from general privacy principles and study their consequences for the protocol design. We also survey to what extent proposals like Microsoft's Passport, IBM's e-Community Single Signon, SAML, Shibboleth, the Liberty Alliance specifications and a protocol BBAE of our own conform to these design consequences, and how one could go forward.