PRIMA: Privacy-Preserving Identity and Access Management at Internet-Scale
نویسندگان
چکیده
The management of identities on the Internet has evolved from the traditional approach (where each service provider stores and manages identities) to a federated identity management system (where the identity management is delegated to a set of identity providers). On the one hand, federated identity ensures usability and provides economic benefits to service providers. On the other hand, it poses serious privacy threats to users as well as service providers. The current technology, which is prevalently deployed on the Internet, allows identity providers to track the user’s behavior across a broad range of services. In this work, we propose PRIMA, a universal credentialbased authentication system for supporting federated identity management in a privacy-preserving manner. Basically, PRIMA does not require any interaction between service providers and identity providers during the authentication process, thus preventing identity providers to profile users’ behavior. Moreover, throughout the authentication process, PRIMA provides a mechanism for controlled disclosure of the users’ private information. We have conducted comprehensive evaluations of the system to show the feasibility of our approach. Our performance analysis shows that an identity provider can process 1,426 to 3,332 requests per second when the key size is varied from 1024 to 2048-bit, respectively.
منابع مشابه
Towards Improved Privacy Policy Coverage in Healthcare Using Policy Refinement
It is now mandatory for healthcare organizations to specify and publish their privacy policies. This has made privacy management initiatives in the healthcare sector increasingly important. However, several recent reports in the public media and the research community about healthcare privacy [1, 2] indicate that the use of privacy policies is not necessarily a strong indication of adequate pri...
متن کاملA centralized privacy-preserving framework for online social networks
There are some critical privacy concerns in the current online social networks (OSNs). Users' information is disclosed to different entities that they were not supposed to access. Furthermore, the notion of friendship is inadequate in OSNs since the degree of social relationships between users dynamically changes over the time. Additionally, users may define similar privacy settings for their f...
متن کاملPrivacy Preserving Dynamic Access Control Model with Access Delegation for eHealth
eHealth is the concept of using the stored digital data to achieve clinical, educational, and administrative goals and meet the needs of patients, experts, and medical care providers. Expansion of the utilization of information technology and in particular, the Internet of Things (IoT) in eHealth, raises various challenges, where the most important one is security and access control. In this re...
متن کاملEnforcement of Individual Privacy Policies for Users of Communication Service Providers plus a Challenge in Online Privacy
Nokia Siemens Networks (NSN) is a leading provider of large-scale solutions for Subscriber Data Management and Identity Management for CSPs. CSPs, similar to other Internet access providers are well-positioned to provide UCIDM services to their users. As CSPs provide their services for a fee, they do not dependent on monetizing personal data of their users. This is especially true in comparison...
متن کاملA Method for Data Minimization in Personal Information Sharing
A fundamental privacy principle, which is enforced in many privacy-enhancing technologies, is data minimization, i.e. the amount of personal data that are revealed to others and extend to which they are processed should be minimized. Privacy-enhancing identity management is important for processing personal data, the purpose of which is to protect personal data. This is especially relevant for ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- CoRR
دوره abs/1612.01787 شماره
صفحات -
تاریخ انتشار 2015