OFELIA - A Secure Mobile Attribute Aggregation Infrastructure for User-Centric Identity Management

被引:0
|
作者
Augusto, Alexandre B. [1 ]
Correia, Manuel Eduardo [1 ]
机构
[1] Univ Porto, Fac Sci, Dept Comp Sci, Ctr Res Adv Comp Syst CRACS INESC LA, P-4100 Oporto, Portugal
关键词
Secure Digital Identity management; User centricity; Mobile Identity Wallet; XMPP; OpenID Connect; Attribute aggregation; Access control;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Personal mobile devices with real practical computational power and Internet connectivity are currently widespread throughout all levels of society. This is so much so that the most popular of these devices, the smart phone, in all its varied ubiquitous manifestations is nowadays the de facto personal mobile computing platform, be it for civil or even military applications. In parallel with these developments, Internet application providers like Google and Facebook are developing and deploying an ever increasing set of personal services that are being aggregated and structured over personal user accounts were an ever increasing set of personal private sensitive attributes is being massively aggregated. In this paper we describe OFELIA (Open Federated Environment for Leveraging of Identity and Authorization), a framework for user centric identity management that provides an identity/authorization versatile infrastructure that does not depend upon the massive aggregation of users identity attributes to offer a versatile set of identity services. In OFELIA personal attributes are distributed among and protected by several otherwise unrelated AAs (Attribute Authorities). Only the user mobile device knows how to aggregate these scattered AAs identity attributes back into some useful identifiable entity identity. Moreover by recurring to an IdB (Identity Broker), acting as a privacy enhancing blind caching-proxy, in OFELIA the identity attributes location in the Internet is hidden from the RP/SP (Relying Party, Service Provider) that wants to have temporary access to the users personal data. The mobile device thus becomes the means by which the user can asynchronously exercise discretionary access control over their most sensitive dynamic identity attributes in a simple but highly transparent way.
引用
收藏
页码:61 / 74
页数:14
相关论文
共 50 条
  • [31] A user-centric approach to information management
    Chakravarthy, S
    Liuzzi, R
    Wong, L
    [J]. IC-AI'2000: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 1-III, 2000, : 287 - 292
  • [32] A User-Centric Approach for Developing Mobile Applications
    Cernezel, Ales
    Hericko, Marjan
    [J]. 7TH INTERNATIONAL CONFERENCE ON KNOWLEDGE MANAGEMENT IN ORGANIZATIONS: SERVICE AND CLOUD COMPUTING, 2013, 172 : 455 - 465
  • [33] Cooperative User-Centric Digital Identity Management Framework for Public Web Portals
    Encheva, Sylvia
    Tumin, Sharil
    [J]. COOPERATIVE DESIGN, VISUALIZATION, AND ENGINEERING, PROCEEDINGS, 2008, 5220 : 273 - +
  • [34] Identifying and Prioritizing Evaluation Criteria for User-Centric Digital Identity Management Systems
    Banihashemi, Sepideh
    Talebpour, Alireza
    Homayounvala, Elaheh
    Abhari, Abdolreza
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2016, 7 (07) : 45 - 54
  • [35] User Centric Identity Management in Mobile Scenarios: The SIMOIT Project
    Eren, Evren
    Uhde, Stephan
    Detken, Kai-Oliver
    [J]. 2009 IEEE INTERNATIONAL WORKSHOP ON INTELLIGENT DATA ACQUISITION AND ADVANCED COMPUTING SYSTEMS: TECHNOLOGY AND APPLICATIONS, 2009, : 615 - +
  • [36] A Framework for User-Centric Visualisation of Blockchain Transactions in Critical Infrastructure
    Tharani, Jeyakumar Samantha
    Ko, Ryan K. L.
    Muthukkumarasamy, Vallipuram
    [J]. PROCEEDINGS OF THE 5TH ACM INTERNATIONAL SYMPOSIUM ON BLOCKCHAIN AND SECURE CRITICAL INFRASTRUCTURE, ACM BSCI 2023, 2023, : 44 - 52
  • [37] On the User-centric Connection Availability of Mobile Wireless Networks
    Xing, Fei
    Wang, Wenye
    [J]. 2011 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2011,
  • [38] Developing a Mobile Learning App: A User-Centric Approach
    Adamu, Muhammad Sadi
    [J]. PROCEEDINGS OF THE FIRST AFRICAN CONFERENCE FOR HUMAN COMPUTER INTERACTION (AFRICHI'16), 2016, : 139 - 143
  • [39] SPOTIFYEXPLAINED: User-centric Mobile Application for Music Exploration
    Savcinsky, Richard
    Peska, Ladislav
    [J]. 2023 ADJUNCT PROCEEDINGS OF THE 31ST ACM CONFERENCE ON USER MODELING, ADAPTATION AND PERSONALIZATION, UMAP 2023, 2023, : 92 - 95
  • [40] A User-Centric Data Secure Creation Scheme in Cloud Computing
    Su Mang
    Li Fenghua
    Shi Guozhen
    Geng Kui
    Xiong Jinbo
    [J]. CHINESE JOURNAL OF ELECTRONICS, 2016, 25 (04) : 753 - 760