Leveraging PKI in SAML 2.0 Federation for Enhanced Discovery Service

Autor: Masaki Shimaoka, Toshiyuki Kataoka, Yasuo Okabe, Noboru Sonehara, Motonori Nakamura, Kazutsuna Yamaji, Takeshi Nishimura
Rok vydání: 2009
Předmět:
Zdroj: SAINT
DOI: 10.1109/saint.2009.56
Popis: The University Public Key Infrastructure (UPKI) project in Japan is developing a national academic inter-institution authentication and authorization infrastructure based on the Public Key Infrastructure (PKI), and it is carrying out a feasibility study on SAML 2.0 federation by building a Shibboleth2.x test-bed called UPKI-Fed with about thirty university participants. Federation usually provides a discovery service (DS, previously called WAYF) to a user since he/she needs to select his/her identity provider (IdP). This IdP selection becomes a serious problem as the number of IdP grows. We solved this problem for a user using client certificate authentication by developing a DS plug-in called DS-PKI Plug-In to leverage securely stored information in a PKI certificate.
Databáze: OpenAIRE