首页> 外文会议>IFIP TC-6 TC-11 International Conference on Communications and Multimedia Security >Using XACML for Privacy Control in SAML-Based Identity Federations
【24h】

Using XACML for Privacy Control in SAML-Based Identity Federations

机译:在基于SAML的身份联合中使用XACML进行隐私控制

获取原文

摘要

With Federated Identity Management (FIM) protocols, service providers can request user attributes, such as the billing address, from the user's identity provider. Access to this information is managed using so-called Attribute Release Policies (ARPs). In this paper, we first analyze various shortcomings of existing ARP implementations; then, we demonstrate that the extensible Access Control Markup Language (XACML) is very suitable for the task. We present an architecture for the integration of XACML ARPs into SAML-based identity providers and specify the policy evaluation workflows. We also introduce our implementation and its integration into the Shibboleth architecture.
机译:利用联合身份管理(FIM)协议,服务提供商可以从用户的身份提供者请求用户属性(例如计费地址)。使用所谓的属性发布策略(ARPS)管理对此信息的访问。在本文中,我们首先分析现有ARP实施的各种缺点;然后,我们证明可扩展访问控制标记语言(XACML)非常适合任务。我们展示了一种将XACML ARP集成到基于SAML的身份提供程序中的架构,并指定策略评估工作流程。我们还介绍了我们的实施及其集成到Shibboleth架构中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号