Fuzzy Authentication Using Interaction Provenance in Service Oriented Computing

Fuzzy Authentication Using Interaction Provenance in Service Oriented Computing
复制标题

面向服务计算中使用交互来源的模糊身份验证

DOI:
--
复制
发表时间:
2015
期刊:
IEEE International Conference on Services Computing
影响因子:
--
通讯作者:
Ragib Hasan
Ragib Hasan
中科院分区:
--
文献类型:
--
作者:
R. Khan;Ragib Hasan

文献摘要

参考文献

被引文献

相似文献

在面向服务的计算中,身份验证因素在单独考虑时存在漏洞。跨平台和服务组合体系结构需要复杂的集成过程,并且限制了新身份验证模型的可接受性。身份验证通常基于二元成功或失败,并且依赖于当前提供的凭据,而不考虑主体如何或何时获得凭据。由此产生的访问控制引擎存在业务策略僵化、管理复杂等问题。相比之下,社会认证是基于彼此之前接触的性质、质量和长度。我们假设人机身份验证是与验证方早期交互的类似因果效应。我们使用这个概念提出交互来源作为面向服务计算中所有身份验证因素的唯一统一表示模型。交互溯源使用过去事件的因果关系来利用服务组合、跨平台集成、时间轴身份验证以及更容易采用新方法。我们利用过去的交互和语言策略,用模糊认证扩展我们的模型。本文提出了一个交互来源记录和认证协议,以及一个具有广泛实验评估的概念验证实现。
In service oriented computing, authentication factors have their vulnerabilities when considered exclusively. Cross-platform and service composition architectures require a complex integration procedure and limit adoptability of newer authentication models. Authentication is generally based on a binary success or failure and relies on credentials proffered at the present moment without considering how or when the credentials were obtained by the subject. The resulting access control engines suffer from rigid service policies and complexity of management. In contrast, social authentication is based on the nature, quality, and length of previous encounters with each other. We posit that human-to-machine authentication is a similar causal effect of an earlier interaction with the verifying party. We use this notion to propose interaction provenance as the only unified representation model for all authentication factors in service oriented computing. Interaction provenance uses the causal relationship of past events to leverage service composition, cross-platform integration, timeline authentication, and easier adoption of newer methods. We extend our model with fuzzy authentication using past interactions and linguistic policies. The paper presents an interaction provenance recording and authentication protocol and a proof-of-concept implementation with extensive experimental evaluation.
基于历史的访问控制和信誉系统的逻辑框架
DOI: 10.3233/jcs-2008-16102
发表时间: 2008
影响因子: 1.2
作者:
Krukow K
通讯作者: Krukow K