Exploratory Research-Scalable Token-Based Authentication: Architectures and Mechanisms
探索性研究-可扩展的基于令牌的身份验证:架构和机制
基本信息
- 批准号:0124873
- 负责人:
- 金额:$ 3.45万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2001
- 资助国家:美国
- 起止时间:2001-09-01 至 2003-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
AbstractThe information revolution has led organizations worldwide to rely heavily on numerous databases to conduct their daily business. Because databases usually exist in broad, highly dynamic network-based environments, formally accessing the resources in a secure manner poses a difficult challenge. Specially, the healthcare industry has recently tried to transit from their old and disparate business models based on ink and paper to a new and consolidated ones based on digitalized information since last a few years for their customers' and stakeholders' needs. In addition, the proposed rules of the Health Insurance Portability and Accountability Act (HIPAA), circulated by the U.S. Department of Health and Human Services (HHS) through the Health Care Financial Administration (HCFA) strongly require the services of security and privacy. Along with this movement, a secure solution for the complex environment like healthcare industry has been highly demanded. Recently, the President's Information Technology Advisory Committee (PITAC) has issued a report about how security can be deployed to modernize the nation's healthcare systems. Nobody has taken a leadership role and demanded investment in information technology. Without active leadership it will be difficult, if not possible, to get the highly decentralized healthcare industry to come up with a standard secure information system.This motivates us to propose a scalable application that can serve as a security tool to the complex environment like healthcare industry. The problem we seek to address in this research is to provide authentication of individual identity in the context of accessing critical information including secure transmission of data across the Internet. These problems have technical solutions that are well known, but the solutions in general are strongly biased toward a single individual interacting with a single application. When an individual needs to access more than one application, or even the same application at a different location or institution, he or she needs another set of electronic keys. In a collaborative and research environment, individuals must collect and maintain a key set of electronic access mechanisms that quickly becomes cumbersome and difficult to manage. For this reason, we focus on token-based solution.In this research, we propose scalable token-based authentication architectures & mechanisms and demonstrate how we can implement them using commercial-off-the-self technologies. Our approach focuses on vendor-neutral specifications including the feasibility of the construction of password, certificate and signature-based authentication mechanisms.
摘要信息革命导致世界各地的组织严重依赖大量的数据库来进行日常业务。由于数据库通常存在于广泛的、高度动态的基于网络的环境中,因此以安全的方式正式访问资源是一项艰巨的挑战。特别是,医疗行业最近试图从基于墨水和纸张的旧的、不同的商业模式过渡到过去几年来基于数字化信息的新的、整合的商业模式,以满足客户和利益相关者的需求。此外,美国卫生与公众服务部(HHS)通过医疗保健财务管理局(HCFA)分发的《健康保险可携带性和问责法》(HIPAA)的拟议规则强烈要求提供安全和隐私服务。伴随着这一运动,对医疗行业等复杂环境的安全解决方案的需求也越来越高。最近,总统的信息技术咨询委员会(PITAC)发布了一份关于如何部署安全措施来实现国家医疗体系现代化的报告。没有人发挥领导作用,要求在信息技术方面进行投资。如果没有积极的领导,高度分散的医疗行业将很难(如果不可能)拿出一个标准的安全信息系统。这促使我们提出一个可扩展的应用程序,它可以作为医疗行业等复杂环境的安全工具。我们在这项研究中试图解决的问题是在访问关键信息的背景下提供对个人身份的认证,包括通过互联网安全地传输数据。这些问题都有众所周知的技术解决方案,但总体来说,这些解决方案强烈偏向于单个人与单个应用程序交互。当一个人需要访问多个应用程序,甚至需要在不同地点或机构访问同一个应用程序时,他或她需要另一套电子钥匙。在协作和研究环境中,个人必须收集和维护一套关键的电子访问机制,这些机制很快就变得繁琐和难以管理。为此,我们将重点放在基于令牌的解决方案上。在本研究中,我们提出了可扩展的基于令牌的认证体系结构和机制,并演示了如何使用商业现成技术来实现它们。我们的方法关注于供应商中立的规范,包括构建基于密码、证书和签名的认证机制的可行性。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Gail-Joon Ahn其他文献
Role-Based Cryptosystem: A New Cryptographic RBAC System Based on Role-Key Hierarchy
基于角色的密码系统:一种基于角色密钥层次结构的新型密码RBAC系统
- DOI:
- 发表时间:
2013 - 期刊:
- 影响因子:6.8
- 作者:
Gail-Joon Ahn;Hongxin Hu;Di Ma;Shanbiao Wang - 通讯作者:
Shanbiao Wang
アイデンティティ管理におけるプライバシー属性オントロジを用いた開示属性の分類
身份管理中使用隐私属性本体的公开属性分类
- DOI:
- 发表时间:
2008 - 期刊:
- 影响因子:0
- 作者:
村上耕平;岩井原瑞穂;Gail-Joon Ahn;吉川正俊 - 通讯作者:
吉川正俊
ソーシャル・ネットワーキング・サービスの相互接続におけるリスク評価を用いたアクセス制御ポリシー設定支援
使用风险评估支持社交网络服务互连的访问控制策略设置
- DOI:
- 发表时间:
2009 - 期刊:
- 影响因子:0
- 作者:
岡野光太郎;岩井原瑞穂;Gail-Joon Ahn;吉川正俊 - 通讯作者:
吉川正俊
可視化から何がわかるのか
我们可以从可视化中学到什么?
- DOI:
- 发表时间:
2009 - 期刊:
- 影响因子:0
- 作者:
岡野光太郎;岩井原瑞穂;Gail-Joon Ahn;吉川正俊;Wenbin Zhang;R. Katsuma;白山晋 - 通讯作者:
白山晋
The user
- DOI:
10.2307/j.ctvxbpgvz.16 - 发表时间:
2020-02 - 期刊:
- 影响因子:0
- 作者:
Gail-Joon Ahn - 通讯作者:
Gail-Joon Ahn
Gail-Joon Ahn的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Gail-Joon Ahn', 18)}}的其他基金
CICI: UCSS: ScienceAccess: Enabling Zero-Trust Resource Access Management for Scientific Collaborations
CICI:UCSS:ScienceAccess:为科学合作实现零信任资源访问管理
- 批准号:
2232911 - 财政年份:2022
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
合作研究:CICI:安全和弹性架构:SciGuard:基于SDN和NFV技术构建科学DMZ安全架构
- 批准号:
1642031 - 财政年份:2017
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
NSF-SFS: Arizona Cyber Defense Scholarship
NSF-SFS:亚利桑那州网络防御奖学金
- 批准号:
1663651 - 财政年份:2017
- 资助金额:
$ 3.45万 - 项目类别:
Continuing Grant
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
III:小:协作研究:以人为本的社交网络中的隐私意识协作数据共享
- 批准号:
1527268 - 财政年份:2015
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Support for the Educational Activities at ACM CCS 2014
支持 ACM CCS 2014 的教育活动
- 批准号:
1426109 - 财政年份:2014
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
TC: Small: Collaborative Proposal: User-Controlled Persona in Virtual Community
TC:小型:协作提案:虚拟社区中用户控制的角色
- 批准号:
0916688 - 财政年份:2009
- 资助金额:
$ 3.45万 - 项目类别:
Continuing Grant
CT-M: Collaborative Research: Securing Dynamic Online Social Networks
CT-M:协作研究:保护动态在线社交网络
- 批准号:
0831360 - 财政年份:2008
- 资助金额:
$ 3.45万 - 项目类别:
Continuing Grant
Collaborative Research: Secure Information Sharing in Internet-based Collaborative Applications
协作研究:基于互联网的协作应用程序中的安全信息共享
- 批准号:
0900970 - 财政年份:2008
- 资助金额:
$ 3.45万 - 项目类别:
Continuing Grant
Collaborative Research: Secure Information Sharing in Internet-based Collaborative Applications
协作研究:基于互联网的协作应用程序中的安全信息共享
- 批准号:
0242393 - 财政年份:2003
- 资助金额:
$ 3.45万 - 项目类别:
Continuing Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: Scalable Nanomanufacturing of Perovskite-Analogue Nanocrystals via Continuous Flow Reactors
合作研究:通过连续流反应器进行钙钛矿类似物纳米晶体的可扩展纳米制造
- 批准号:
2315997 - 财政年份:2024
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Collaborative Research: SHF: Small: Efficient and Scalable Privacy-Preserving Neural Network Inference based on Ciphertext-Ciphertext Fully Homomorphic Encryption
合作研究:SHF:小型:基于密文-密文全同态加密的高效、可扩展的隐私保护神经网络推理
- 批准号:
2412357 - 财政年份:2024
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
CC* Networking Infrastructure: Building a Scalable and Polymorphic Cyberinfrastructure for Diverse Research and Education Needs at Illinois State University
CC* 网络基础设施:为伊利诺伊州立大学的多样化研究和教育需求构建可扩展和多态的网络基础设施
- 批准号:
2346712 - 财政年份:2024
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Collaborative Research: Scalable Manufacturing of Large-Area Thin Films of Metal-Organic Frameworks for Separations Applications
合作研究:用于分离应用的大面积金属有机框架薄膜的可扩展制造
- 批准号:
2326714 - 财政年份:2024
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Collaborative Research: Scalable Manufacturing of Large-Area Thin Films of Metal-Organic Frameworks for Separations Applications
合作研究:用于分离应用的大面积金属有机框架薄膜的可扩展制造
- 批准号:
2326713 - 财政年份:2024
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Collaborative Research: Scalable Nanomanufacturing of Perovskite-Analogue Nanocrystals via Continuous Flow Reactors
合作研究:通过连续流反应器进行钙钛矿类似物纳米晶体的可扩展纳米制造
- 批准号:
2315996 - 财政年份:2024
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Collaborative Research: Scalable Circuit theoretic Framework for Large Grid Simulations and Optimizations: from Combined T&D Planning to Electromagnetic Transients
协作研究:大型电网仿真和优化的可扩展电路理论框架:来自组合 T
- 批准号:
2330195 - 财政年份:2024
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Collaborative Research: Scalable Circuit theoretic Framework for Large Grid Simulations and Optimizations: from Combined T&D Planning to Electromagnetic Transients
协作研究:大型电网仿真和优化的可扩展电路理论框架:来自组合 T
- 批准号:
2330196 - 财政年份:2024
- 资助金额:
$ 3.45万 - 项目类别:
Standard Grant
Creating harmonised and scalable methods and tools for constructing households in large diverse administrative and health research datasets
创建统一且可扩展的方法和工具,用于在大型多样化的行政和健康研究数据集中构建家庭
- 批准号:
ES/X00046X/1 - 财政年份:2023
- 资助金额:
$ 3.45万 - 项目类别:
Research Grant
Collaborative Research: IMR: MM-1A: Scalable Statistical Methodology for Performance Monitoring, Anomaly Identification, and Mapping Network Accessibility from Active Measurements
合作研究:IMR:MM-1A:用于性能监控、异常识别和主动测量映射网络可访问性的可扩展统计方法
- 批准号:
2319592 - 财政年份:2023
- 资助金额:
$ 3.45万 - 项目类别:
Continuing Grant