首页> 外文会议>International symposium on intelligent distributed computing >Authorize-then-Authenticate: Supporting Authorization Decisions Prior to Authentication in an Electronic Identity Infrastructure
【24h】

Authorize-then-Authenticate: Supporting Authorization Decisions Prior to Authentication in an Electronic Identity Infrastructure

机译:先授权再授权:在电子身份基础结构中进行身份验证之前支持授权决策

获取原文

摘要

Federated electronic identity systems are increasingly used in commercial and public services to let users share their identity across providers. We discuss authorization (prior to authentication) issues in the elDAS federated European electronic identity infrastructure. In this scenario, each European country runs a national elDAS node, which transfers personal attributes upon successful authentication of a person in his home country. Service Providers in foreign countries use these attributes to take (local) authorization decisions for the requested service. Our work addresses those scenarios where authorization is required prior to authentication (authorise-then-authenticate), that is when a service provider has to implement access control decisions before the person has been authenticated. This scenario applies for example in an user-centric network access service. We propose two models to perform authorise-then-authenticate in elDAS, one working at application level and one at transport level, and we sketch a possible implementation scenario.
机译:联邦电子身份系统越来越多地用于商业和公共服务中,以使用户在提供商之间共享其身份。我们将在elDAS联合的欧洲电子身份基础结构中讨论授权(在身份验证之前)问题。在这种情况下,每个欧洲国家/地区都运行一个国家的elDAS节点,该节点在成功获得本国人员的身份验证后会转移个人属性。国外的服务提供商使用这些属性来为请求的服务做出(本地)授权决定。我们的工作解决了在身份验证之前需要授权(授权然后身份验证)的情况,即服务提供商必须在对人员进行身份验证之前实施访问控制决策。例如,此方案适用于以用户为中心的网络访问服务。我们提出了两种在elDAS中执行授权然后认证的模型,一种模型在应用程序级别工作,另一种模型在传输级别工作,并勾勒出一种可能的实现方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号