A Dynamic Federated Identity Management Using OpenID Connect

被引:0
|
作者
Alsadeh, Ahmad [1 ]
Yatim, Nasri [2 ]
Hassouneh, Yousef [2 ]
机构
[1] Birzeit Univ, Elect & Comp Engn Dept, POB 14, Birzeit, Palestine
[2] Birzeit Univ, Comp Sci Dept, POB 14, Birzeit, Palestine
来源
FUTURE INTERNET | 2022年 / 14卷 / 11期
关键词
identity management; identity federation; OpenID connect; dynamic client registration;
D O I
10.3390/fi14110339
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Identity federation allows one to link a user's digital identities across several identity management systems. Federated identity management (FIM) ensures that users have easy access to the available resources. However, scaling FIM to numerous partners is a challenging process due to the interoperability issue between different federation architectures. This study proposes a dynamic identity federation model to eliminate the manual configuration steps needed to establish an organizational identity federation by utilizing the OpenID Connect (OIDC) framework. The proposed model consists of three major steps to establish dynamic FIM: first, the discovery of the OpenID service provider, which indicates the location of the partner organization; second, the registration of the OpenID relying party, which allows the organization and its partner to negotiate information for establishing the federation; finally, establishing the dynamic trust federation. The proposed dynamic FIM model allows applications to provide services to end-users coming from various domains while maintaining a trust between clients and service providers. Through our proposed dynamic identity federation model, organizations can save hundreds of hours by achieving dynamic federation in runtime and serving a large number of end-users.
引用
收藏
页数:19
相关论文
共 50 条
  • [41] Efficient Attribute Management in a Federated Identity Management Infrastructure
    Berbecaru, Diana
    Lioy, Antonio
    2016 24TH EUROMICRO INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED, AND NETWORK-BASED PROCESSING (PDP), 2016, : 590 - 595
  • [42] Identity Manage Interoperation Based on OpenID
    Yu, Shaofeng
    Li, Dongmei
    Chen, Jianyong
    ADVANCES IN SWARM INTELLIGENCE, ICSI 2012, PT II, 2012, 7332 : 360 - 367
  • [43] Dynamic Management of Identity Federations using Blockchain
    Alom, Ifteher
    Eshita, Romana Mahjabin
    Harun, Anam Ibna
    Ferdous, Md Sadek
    Shuhan, Mirza Kamrul Bashar
    Chowdhury, Mohammad Jabed M.
    Rahman, Mohammad Shahidur
    2021 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (ICBC), 2021,
  • [44] Notarized federated identity management for web services
    Goodrich, Michael T.
    Tamassia, Roberto
    Yao, Danfeng
    DATA AND APPLICATIONS SECURITY XX, PROCEEDINGS, 2006, 4127 : 133 - 147
  • [45] Federated Identity and Access Management for the Internet of Things
    Fremantle, Paul
    Aziz, Benjamin
    Kopecky, Jacek
    Scott, Philip
    2014 INTERNATIONAL WORKSHOP ON SECURE INTERNET OF THINGS (SIOT), 2014, : 10 - 17
  • [46] Enabling the Autonomic Management of Federated Identity Providers
    Bailey, Christopher
    Chadwick, David W.
    de Lemos, Rogerio
    Siu, Kristy W. S.
    EMERGING MANAGEMENT MECHANISMS FOR THE FUTURE INTERNET (AIMS 2013), 2013, 7943 : 100 - 111
  • [47] A Survey of Security Analysis in Federated Identity Management
    Simpson, Sean
    Gross, Thomas
    PRIVACY AND IDENTITY MANAGEMENT: FACING UP TO NEXT STEPS, 2016, 498 : 231 - 247
  • [48] Achieving Privacy in a Federated Identity Management System
    Landau, Susan
    Le Van Gong, Hubert
    Wilton, Robin
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, 2009, 5628 : 51 - 70
  • [49] A Review of Federated Identity Management of OpenStack Cloud
    Shere, Rohit
    Srivastava, Sonika
    Pateriya, R. K.
    2017 INTERNATIONAL CONFERENCE ON RECENT INNOVATIONS IN SIGNAL PROCESSING AND EMBEDDED SYSTEMS (RISE), 2017, : 516 - 520
  • [50] Ensuring information assurance in federated identity management
    Shin, D
    Ahn, GJ
    Shenoy, P
    CONFERENCE PROCEEDINGS OF THE 2004 IEEE INTERNATIONAL PERFORMANCE, COMPUTING, AND COMMUNICATIONS CONFERENCE, 2004, : 821 - 826