A client-side approach for privacy-preserving identity federation

Identity in the Information Society 2 (3):269-295 (2009)
  Copy   BIBTEX

Abstract

Providing Single Sign-On (SSO) between service providers and enabling service providers to share user personal attributes are critical for both users to benefit from a seamless access to their services, and service providers to realize new business opportunities. Today, however, the users have several independent, partial identities spread over different service providers. Providing SSO and attribute sharing requires that links (federations) are established between (partial) identities. In SAML 2.0 (Maler et al. 2003), the links between identities are stored and managed at the network side by the identity providers (network-side identity federation). This model prevents the service providers from mass-correlating the partial identities they have, but the users must fully trust the identity providers. In this paper, we propose a complementary approach where the users have a full control of the links between their partial identities. It is a client-side identity federation approach, which relies on the introduction of a new cryptographic tool, called invariable partially blind signature scheme, that may be of independent interest

Links

PhilArchive



    Upload a copy of this work     Papers currently archived: 93,031

External links

Setup an account with your affiliations in order to access resources via your University's proxy server

Through your library

Similar books and articles

Accountable privacy supporting services.Jan Camenisch, Thomas Groß & Thomas Scott Heydt-Benjamin - 2009 - Identity in the Information Society 2 (3):241-267.

Analytics

Added to PP
2013-11-24

Downloads
12 (#1,113,725)

6 months
4 (#863,447)

Historical graph of downloads
How can I increase my downloads?

Citations of this work

No citations found.

Add more citations

References found in this work

No references found.

Add more references