Autor: |
Hommel, Wolfgang, Grabatin, Michael, Metzger, Stefan, Pöhn, Daniela |
Zdroj: |
PIK - Praxis der Informationsverarbeitung und Kommunikation; April 2017, Vol. 39 Issue: 3-4 p41-50, 10p |
Abstrakt: |
Accessing remote IT services through identity federations (IFs) is based on solid technical protocols such as the Security Assertion Markup Language (SAML) and OpenID Connect. However, reliable delegated user authentication and authorization also pose organizational challenges regarding the quality management of user data. Level of Assurance (LoA) concepts have been adapted and applied to IFs, but their inhomogeneous proliferation bears the risk of aggravating instead of simplifying the manual work steps. This is increased by the providing IT services for multiple or dynamically set up IFs. This article presents a novel LoA management approach that has been designed for a high degree of automation, adopts the approach for the dynamic metadata exchange by GÉANT-TrustBroker and exemplifies its usage. |
Databáze: |
Supplemental Index |
Externí odkaz: |
|