A Privacy Oriented Extension of Attribute Exchange in Shibboleth

A Privacy Oriented Extension of Attribute Exchange in Shibboleth
复制标题

Shibboleth 中属性交换的面向隐私的扩展

DOI:
10.1109/saint-w.2007.13
复制
发表时间:
2006
期刊:
2007 International Symposium on Applications and the Internet Workshops
影响因子:
--
通讯作者:
Y. Okabe
Y. Okabe
中科院分区:
--
文献类型:
--
作者:
Shoichirou Fujiwara;T. Komura;Y. Okabe

文献摘要

被引文献

相似文献

在SAML、Liberty或Shibboleth等Web服务框架中,用户可以通过要求自己的身份提供商(IdP)发布安全断言来获得身份验证,通过该断言可以访问SP(服务提供商)的服务。如果SP另外请求某人的某些属性,则用户被迫透露这些属性的直接值。在某些情况下,用户必须提供详细的隐私信息,而SP实际上并不需要这些信息来授权他们。本文以Shibboleth为研究对象,对Shibboleth中IdP和SP之间的属性交换协议进行了扩展。在传统的Shibboleth框架中,属性是以立即值交换的,而在我们的扩展中,SP请求IdP测试用户的属性是否满足某些条件,然后IdP向SP返回“真”、“假”或“不可回答”。我们指定一种语言来将条件描述为SP处的查询。我们还在IdP扩展了属性授权,以评估来自SP的条件
In frameworks for Web services like SAML, liberty or Shibboleth, a user can get authentication by asking one's IdP (identity provider) to issue a security assertion by which one can get access to services at an SP (service provider). If the SP additionally requests some attributes of one's, the user is forced to reveal the immediate values of them. There are cases where users must present detailed privacy information which SPs don't actually require to authorize them. We focus on Shibboleth and propose an extension of the attribute exchange protocol between an IdP and an SP in Shibboleth. While in the conventional framework of Shibboleth attributes are exchanged in immediate value, in our extension an SP requests an IdP to test whether user's attributes are satisfied some conditions, then the IdP returns either "true", "false" or "unanswerable" to the SP. We specify a language to describe the conditions as a query at the SP. We also extend an attribute authority at the IdP to evaluate the conditions presented from the SP