Potential Impacts in Citizens' Privacy of using Federated Identity Management to Offer e-Government Services

被引:2
|
作者
Navas, Jorge [1 ]
Beltran, Marta [1 ]
机构
[1] Univ Rey Juan Carlos, Dept Comp, ETSII, Madrid, Spain
关键词
e-Government; Federated Identity Management (FIM); Mobile Connect; OpenID Connect; Privacy; SAML; Threat Modelling;
D O I
10.5220/0007797703500355
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The ability to verify citizens' identity and to authenticate and to authorize them when accessing to eGovernment services (such as on-line voting, licence renewal or tax payment) is crucial for the digital transformation of public administrations. Governments need identity management mechanisms valid across different services, platforms, devices, technologies and even physical borders. Federated Identity Management (FIM) can help in ensuring secure identity management, in improving citizens' experience and in increasing services' accessibility. But this comes with a price since relying on Identity Providers, whether public or private, poses new privacy threats that has to be faced. This paper presents a threat model of the most promising and extended FIM specifications, OpenID Connect and Mobile Connect, when used as federated identity management solutions for e-Government services. A set of three improvements is proposed to avoid these threats or to mitigate their impacts, taking into account both, specification and implementation aspects. Furthermore, guidelines and recommendations in order to improve future versions of the specifications and/or their implementations are provided for developers, providers and policy makers.
引用
收藏
页码:350 / 355
页数:6
相关论文
共 50 条
  • [1] CONTROL OF CITIZENS' IDENTITY WHEN ACCESSING PUBLIC SERVICES E-GOVERNMENT AND THE DEFENCE OF PRIVACY
    Rodriguez Ayuso, Juan Francisco
    [J]. REVISTA GENERAL DE DERECHO ADMINISTRATIVO, 2021, (57):
  • [2] Citizens' supporting services by E-Government
    Gruhn, Volker
    Schöpe, Lothar
    [J]. IT - Information Technology, 2002, 44 (03): : 119 - 127
  • [3] E-government business strategies and services to citizens
    Chamberlain, J
    Castleman, T
    [J]. SEEKING SUCCESS IN E-BUSINESS: A MULTIDISCIPLINARY APPROACH, 2003, 123 : 309 - 325
  • [4] On stimulus for citizens' use of e-government services
    Bavec, Cene
    [J]. 2008 INTERNATIONAL MULTICONFERENCE ON COMPUTER SCIENCE AND INFORMATION TECHNOLOGY (IMCSIT), VOLS 1 AND 2, 2008, : 360 - 364
  • [5] Impact of Citizens' Privacy Concerns on e-Government Adoption
    Liu, Dapeng
    Carter, Lemuria
    [J]. PROCEEDINGS OF THE 19TH ANNUAL INTERNATIONAL CONFERENCE ON DIGITAL GOVERNMENT RESEARCH (DGO 2018): GOVERNANCE IN THE DATA AGE, 2018, : 240 - 245
  • [6] Citizens and E-Government Evaluating Policy and Management
    Keele, Benjamin J.
    [J]. GOVERNMENT INFORMATION QUARTERLY, 2012, 29 (02) : 307 - 307
  • [7] E-Government as a quality improvement tool for citizens' services
    Gasova, Katarina
    Stofkova, Katarina
    [J]. 12TH INTERNATIONAL SCIENTIFIC CONFERENCE OF YOUNG SCIENTISTS ON SUSTAINABLE, MODERN AND SAFE TRANSPORT, 2017, 192 : 225 - 230
  • [8] Delivering e-Government services to citizens and businesses: The government gateway concept
    Sebek, J
    [J]. ELECTRONIC GOVENMENT, PROCEEDINGS, 2003, 2739 : 125 - 128
  • [9] Delivering E-government services to citizens and businesses: The Government Gateway concept
    Sebek, Jan
    [J]. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2003, 2739 : 125 - 128
  • [10] Privacy Requirements Engineering for Trustworthy e-Government Services
    Vrakas, Nikos
    Kalloniatis, Christos
    Tsohou, Aggeliki
    Lambrinoudakis, Costas
    [J]. TRUST AND TRUSTWORTHY COMPUTING, PROCEEDINGS, 2010, 6101 : 298 - +