دورية أكاديمية

Making identity assurance and authentication strength work for federated infrastructures

التفاصيل البيبلوغرافية
العنوان: Making identity assurance and authentication strength work for federated infrastructures
المؤلفون: Ziegler, J. A., Stevanovic, U., Groep, D., Neilson, I., Kelsey, D. P., Kremers, M.
المصدر: ISSN: 1824-8039.
بيانات النشر: Scuola Internazionale Superiore di Studi Avanzati
سنة النشر: 2021
المجموعة: KITopen (Karlsruhe Institute of Technologie)
مصطلحات موضوعية: ddc:620, Engineering & allied operations, info:eu-repo/classification/ddc/620
الوصف: In both higher Research and Education (R&E) as well as in research-/ e-infrastructures (in short: infrastructures), federated access and single sign-on by way of national federations, operated in most cases by NRENs, are used as a means to provide users with access to a variety of services. Whereas in national federations institutional accounts, e.g. provided by a university, are typically used to access services, many infrastructures also accept other sources of identity: provided by ''community identity providers'', social identity providers, or governmental IDs. In order to assess and communicate the quality of identities being used and authentications being performed, so called Level of Assurance (LoA) frameworks are used. Because sophisticated LoA frameworks like NIST 800-63-3, Kantara IAF 1420 or eIDAS regulation are often considered too complex to be used in R&E scenarios, the REFEDS Assurance Suite, a more lightweight approach, has been developed. To select an appropriate assurance level, Service Providers need to weigh risks and potential harms in relation to the kind of service they offer. However, the management of risks is often implicitly assumed and little or no guidance to determine the appropriate assurance level is given. In this paper, first, common LoA frameworks and their relation to risk management are investigated. Following that, their components are compared against the REFEDS Assurance Suite using a graphical representation. The focus of this paper lies in providing guidance and best practices based on example scenarios for both Service Providers to request the appropriate REFEDS assurance level, as well as for Identity Provider operators on how to implement REFEDS assurance components.
نوع الوثيقة: article in journal/newspaper
conference object
وصف الملف: application/pdf
اللغة: English
العلاقة: Proceedings of Science; info:eu-repo/semantics/altIdentifier/issn/1824-8039; https://publikationen.bibliothek.kit.edu/1000140364Test; https://publikationen.bibliothek.kit.edu/1000140364/134403588Test; https://doi.org/10.5445/IR/1000140364Test
DOI: 10.5445/IR/1000140364
الإتاحة: https://doi.org/10.5445/IR/1000140364Test
https://doi.org/10.22323/1.378.0029Test
https://publikationen.bibliothek.kit.edu/1000140364Test
https://publikationen.bibliothek.kit.edu/1000140364/134403588Test
حقوق: https://creativecommons.org/licenses/by-nc-nd/4.0/deed.deTest ; info:eu-repo/semantics/openAccess
رقم الانضمام: edsbas.EBDCD082
قاعدة البيانات: BASE