دورية أكاديمية
Making identity assurance and authentication strength work for federated infrastructures
العنوان: | Making identity assurance and authentication strength work for federated infrastructures |
---|---|
المؤلفون: | Ziegler, J. A., Stevanovic, U., Groep, D., Neilson, I., Kelsey, D. P., Kremers, M. |
المصدر: | ISSN: 1824-8039. |
بيانات النشر: | Scuola Internazionale Superiore di Studi Avanzati |
سنة النشر: | 2021 |
المجموعة: | KITopen (Karlsruhe Institute of Technologie) |
مصطلحات موضوعية: | ddc:620, Engineering & allied operations, info:eu-repo/classification/ddc/620 |
الوصف: | In both higher Research and Education (R&E) as well as in research-/ e-infrastructures (in short: infrastructures), federated access and single sign-on by way of national federations, operated in most cases by NRENs, are used as a means to provide users with access to a variety of services. Whereas in national federations institutional accounts, e.g. provided by a university, are typically used to access services, many infrastructures also accept other sources of identity: provided by ''community identity providers'', social identity providers, or governmental IDs. In order to assess and communicate the quality of identities being used and authentications being performed, so called Level of Assurance (LoA) frameworks are used. Because sophisticated LoA frameworks like NIST 800-63-3, Kantara IAF 1420 or eIDAS regulation are often considered too complex to be used in R&E scenarios, the REFEDS Assurance Suite, a more lightweight approach, has been developed. To select an appropriate assurance level, Service Providers need to weigh risks and potential harms in relation to the kind of service they offer. However, the management of risks is often implicitly assumed and little or no guidance to determine the appropriate assurance level is given. In this paper, first, common LoA frameworks and their relation to risk management are investigated. Following that, their components are compared against the REFEDS Assurance Suite using a graphical representation. The focus of this paper lies in providing guidance and best practices based on example scenarios for both Service Providers to request the appropriate REFEDS assurance level, as well as for Identity Provider operators on how to implement REFEDS assurance components. |
نوع الوثيقة: | article in journal/newspaper conference object |
وصف الملف: | application/pdf |
اللغة: | English |
العلاقة: | Proceedings of Science; info:eu-repo/semantics/altIdentifier/issn/1824-8039; https://publikationen.bibliothek.kit.edu/1000140364Test; https://publikationen.bibliothek.kit.edu/1000140364/134403588Test; https://doi.org/10.5445/IR/1000140364Test |
DOI: | 10.5445/IR/1000140364 |
الإتاحة: | https://doi.org/10.5445/IR/1000140364Test https://doi.org/10.22323/1.378.0029Test https://publikationen.bibliothek.kit.edu/1000140364Test https://publikationen.bibliothek.kit.edu/1000140364/134403588Test |
حقوق: | https://creativecommons.org/licenses/by-nc-nd/4.0/deed.deTest ; info:eu-repo/semantics/openAccess |
رقم الانضمام: | edsbas.EBDCD082 |
قاعدة البيانات: | BASE |
DOI: | 10.5445/IR/1000140364 |
---|