User-Centric Privacy for Identity Federations Based on a Recommendation System

被引:0
|
作者
Villaran, Carlos [1 ]
Beltran, Marta [1 ]
机构
[1] Univ Rey Juan Carlos, ETSII, Dept Comp, C Tulipan S-N, Mostoles 28933, Spain
关键词
identity infrastructures; federated identity management; privacy; recommendation system;
D O I
10.3390/electronics11081238
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Specifications such as SAML, OAuth, OpenID Connect and Mobile Connect are essential for solving identification, authentication and authorisation in contexts such as mobile apps, social networks, e-commerce, cloud computing or the Internet of Things. However, end-users relying on identity providers to access resources, applications or services lose control over the Personally Identifiable Information (PII) they share with the different providers composing identity federations. This work proposes a user-centric approach based on a recommendation system to support users in making privacy decisions such as selecting service providers or choosing their privacy settings. The proposed Privacy Advisor gives end-users privacy protection by providing personalised recommendations without compromising the identity federations' functionalities or requiring any changes in their underlying specifications. A proof of concept of the proposed recommendation system is presented to validate and evaluate its utility and feasibility.
引用
收藏
页数:18
相关论文
共 50 条
  • [21] Designing Privacy for You: A Practical Approach for User-Centric Privacy
    Senarath, Awanthika
    Arachchilage, Nalin A. G.
    Slay, Jill
    HUMAN ASPECTS OF INFORMATION SECURITY, PRIVACY AND TRUST (HAS 2017), 2017, 10292 : 739 - 752
  • [22] A Smart Card Based Solution for User-Centric Identity Management
    Vossaert, Jan
    Verhaeghe, Pieter
    De Decker, Bart
    Naessens, Vincent
    PRIVACY AND IDENTITY MANAGEMENT FOR LIFE, 2011, 352 : 164 - +
  • [23] Personalized identity agent for User-Centric IdM
    Kim, Seung-Hyun
    Ko, Han-Gyu
    Choi, Daeseon
    Kim, Soo Hyung
    Jin, Seunghun
    10TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III: INNOVATIONS TOWARD FUTURE NETWORKS AND SERVICES, 2008, : 1308 - +
  • [24] A USER-CENTRIC APPROACH FOR FEDERATED IDENTITY MANAGEMENT
    Bergadano, Francesco
    Accornero, Renato
    Lucisano, Giovanna
    Rispoli, Daniele
    INTERNATIONAL JOURNAL ON INFORMATION TECHNOLOGIES AND SECURITY, 2013, 5 (01): : 3 - 18
  • [25] User-Centric Handling of Identity Agent Compromise
    Mashima, Daisuke
    Ahamad, Mustaque
    Kannan, Swagath
    COMPUTER SECURITY - ESORICS 2009, PROCEEDINGS, 2009, 5789 : 19 - 36
  • [26] OpenID as an Approach for User-centric Identity Management
    Bitzer, Stefan
    Klein, Marco
    Schumann, Matthias
    AMCIS 2010 PROCEEDINGS, 2010,
  • [27] User-Centric Path Reasoning towards Explainable Recommendation
    Tai, Chang-You
    Huang, Liang-Ying
    Huang, Chien-Kun
    Ku, Lun-Wei
    SIGIR '21 - PROCEEDINGS OF THE 44TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, 2021, : 879 - 889
  • [28] User-Centric Conversational Recommendation with Multi-Aspect User Modeling
    Li, Shuokai
    Xie, Ruobing
    Zhu, Yongchun
    Ao, Xiang
    Zhuang, Fuzhen
    He, Qing
    PROCEEDINGS OF THE 45TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL (SIGIR '22), 2022, : 223 - 233
  • [29] Assessing Privacy Risks in Android: A User-Centric Approach
    Mylonas, Alexios
    Theoharidou, Marianthi
    Gritzalis, Dimitris
    RISK ASSESSMENT AND RISK-DRIVEN TESTING, RISK 2013, 2014, 8418 : 21 - 37
  • [30] Cloud Computing Privacy Issues and User-Centric Solution
    Lijo, V. P.
    Kalady, Saidalavi
    COMPUTER NETWORKS AND INTELLIGENT COMPUTING, 2011, 157 : 448 - 456