Exploratory Research-Scalable Token-Based Authentication: Architectures and Mechanisms
Exploratory Research-Scalable Token-Based Authentication: Architectures and Mechanisms
批准号:
0124873
负责人:
Gail-Joon Ahn
金额:
$3.45万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2001
资助国家:
美国
项目状态:
已结题
起止时间:
2001-09-01 至 2003-08-31
中文摘要
摘要信息革命导致世界范围内的组织严重依赖大量数据库来开展日常业务。由于数据库通常存在于广泛的、高度动态的基于网络的环境中,因此以安全的方式正式访问资源是一项艰巨的挑战。特别是,为了满足客户和利益相关者的需求,医疗保健行业最近试图从基于墨水和纸张的旧的、不同的商业模式过渡到基于数字化信息的新的、统一的商业模式。此外,美国卫生与公众服务部(HHS)通过卫生保健财务管理局(HCFA)发布的《健康保险流通与责任法案》(HIPAA)的拟议规则强烈要求提供安全和隐私服务。随着这一趋势,人们对医疗保健行业等复杂环境的安全解决方案提出了很高的要求。最近,总统信息技术咨询委员会(PITAC)发布了一份关于如何部署安全以实现国家医疗保健系统现代化的报告。没有人发挥领导作用,要求对信息技术进行投资。如果没有积极的领导,将很难(如果不可能的话)让高度分散的医疗保健行业提出一个标准的安全信息系统。这促使我们提出一种可扩展的应用程序,它可以作为医疗保健行业等复杂环境的安全工具。在这项研究中,我们试图解决的问题是在访问关键信息的背景下提供个人身份认证,包括在互联网上安全传输数据。这些问题有众所周知的技术解决方案,但是这些解决方案通常强烈倾向于单个人与单个应用程序进行交互。当个人需要访问多个应用程序,甚至在不同地点或机构访问同一个应用程序时,他或她需要另一组电子密钥。在协作和研究环境中,个人必须收集和维护一套关键的电子访问机制,这些机制很快就变得繁琐和难以管理。出于这个原因,我们专注于基于令牌的解决方案。在本研究中,我们提出了可扩展的基于令牌的身份验证架构和机制,并演示了如何使用商用技术实现它们。我们的方法侧重于供应商中立的规范,包括构建基于密码、证书和签名的身份验证机制的可行性。
英文摘要
AbstractThe information revolution has led organizations worldwide to rely heavily on numerous databases to conduct their daily business. Because databases usually exist in broad, highly dynamic network-based environments, formally accessing the resources in a secure manner poses a difficult challenge. Specially, the healthcare industry has recently tried to transit from their old and disparate business models based on ink and paper to a new and consolidated ones based on digitalized information since last a few years for their customers' and stakeholders' needs. In addition, the proposed rules of the Health Insurance Portability and Accountability Act (HIPAA), circulated by the U.S. Department of Health and Human Services (HHS) through the Health Care Financial Administration (HCFA) strongly require the services of security and privacy. Along with this movement, a secure solution for the complex environment like healthcare industry has been highly demanded. Recently, the President's Information Technology Advisory Committee (PITAC) has issued a report about how security can be deployed to modernize the nation's healthcare systems. Nobody has taken a leadership role and demanded investment in information technology. Without active leadership it will be difficult, if not possible, to get the highly decentralized healthcare industry to come up with a standard secure information system.This motivates us to propose a scalable application that can serve as a security tool to the complex environment like healthcare industry. The problem we seek to address in this research is to provide authentication of individual identity in the context of accessing critical information including secure transmission of data across the Internet. These problems have technical solutions that are well known, but the solutions in general are strongly biased toward a single individual interacting with a single application. When an individual needs to access more than one application, or even the same application at a different location or institution, he or she needs another set of electronic keys. In a collaborative and research environment, individuals must collect and maintain a key set of electronic access mechanisms that quickly becomes cumbersome and difficult to manage. For this reason, we focus on token-based solution.In this research, we propose scalable token-based authentication architectures & mechanisms and demonstrate how we can implement them using commercial-off-the-self technologies. Our approach focuses on vendor-neutral specifications including the feasibility of the construction of password, certificate and signature-based authentication mechanisms.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: UCSS: ScienceAccess: Enabling Zero-Trust Resource Access Management for Scientific Collaborations
-
批准号:2232911
-
项目类别:Standard Grant
-
资助金额:$59.17万
-
财政年份:2022
-
负责人:Gail-Joon Ahn
-
依托单位:
Collaborative Research: CICI: Secure and Resilient Architecture: SciGuard: Building a Security Architecture for Science DMZ Based on SDN and NFV Technologies
-
批准号:1642031
-
项目类别:Standard Grant
-
资助金额:$49.95万
-
财政年份:2017
-
负责人:Gail-Joon Ahn
-
依托单位:
NSF-SFS: Arizona Cyber Defense Scholarship
-
批准号:1663651
-
项目类别:Continuing Grant
-
资助金额:$399.78万
-
财政年份:2017
-
负责人:Gail-Joon Ahn
-
依托单位:
III: Small: Collaborative Research: Privacy-Aware Collaborative Data Sharing in Human-Centered Social Networks
-
批准号:1527268
-
项目类别:Standard Grant
-
资助金额:$20.0万
-
财政年份:2015
-
负责人:Gail-Joon Ahn
-
依托单位:
Support for the Educational Activities at ACM CCS 2014
-
批准号:1426109
-
项目类别:Standard Grant
-
资助金额:$2.0万
-
财政年份:2014
-
负责人:Gail-Joon Ahn
-
依托单位:
TC: Small: Collaborative Proposal: User-Controlled Persona in Virtual Community
-
批准号:0916688
-
项目类别:Continuing Grant
-
资助金额:$26.99万
-
财政年份:2009
-
负责人:Gail-Joon Ahn
-
依托单位:
CT-M: Collaborative Research: Securing Dynamic Online Social Networks
-
批准号:0831360
-
项目类别:Continuing Grant
-
资助金额:$50.0万
-
财政年份:2008
-
负责人:Gail-Joon Ahn
-
依托单位:
Collaborative Research: Secure Information Sharing in Internet-based Collaborative Applications
-
批准号:0900970
-
项目类别:Continuing Grant
-
资助金额:$6.17万
-
财政年份:2008
-
负责人:Gail-Joon Ahn
-
依托单位:
Collaborative Research: Secure Information Sharing in Internet-based Collaborative Applications
-
批准号:0242393
-
项目类别:Continuing Grant
-
资助金额:$13.0万
-
财政年份:2003
-
负责人:Gail-Joon Ahn
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: