Federated and Service-Oriented Identity Management at a University

نویسندگان

  • Frank Schell
  • Thorsten Höllrigl
  • Hannes Hartenstein
چکیده

1. EXECUTIVE SUMMARY In this contribution we state the following thesis: The concept of federation represents a promising way to ease the establishment and operation of organizational and technical issues of identity management at a university. This concept fits well for most universities due to the fact that typically universities consist of " somewhat " independent organizational units like library, computing center, administration and various faculties, with each having their own identity repository or even local identity management. We show two main advantages of this conceptual view of a university. On the one side the identity management can be build up successively in a step-by-step manner. On the other side the organizational units are seen as satellites with each needing just one or a small number of interfaces to the overall identity management system thus setting up a kind of hierarchy of identity management systems. This system can use different technologies, namely identity as a service and (de-)provisioning, to provide identity information to the organizational units and processes across the university. We exemplify how to integrate a satellite in the federation. Another contribution is the structuring of the establishment of a federation by categorizing artifacts and components in four models and by proposing a reasonable sequence of phases. This classification distinguishes between information, functional, communication and organizational aspects known from the integrated management of distributed systems. We conclude the paper with a discussion reflecting our experiences gained while setting up an identity management for a university.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Service Oriented Federated Identity System Framework

The rapid evolution of network and distributed computing, such as Service Oriented Architecture (SOA), is increasing the challenge of securely controlling access to enterprise IT resources. As gaining access to distributed resources becomes increasingly vital, the ability to make sure that the right people have secure access to the right information at the right time becomes a critical requirem...

متن کامل

PROVIDING NATIVE SUPPORT FOR FEDERATED IDENTITY MANAGEMENT IN A BUSINESS-PROCESS-MANAGEMENT SYSTEM Identity Business Processes

To facilitate information-system security, e. g., access control or audit, the entities involved play a key role. This makes identity management an important task. The success of service-oriented architectures (SOA) has lead to the development of federated identity management (FIM), to deal with the dynamic nature of SOA and to achieve economies of scale. Business processes in SOA are a composi...

متن کامل

Service Oriented Computing

Service-oriented Architectures (SOA) facilitate the dynamic and seamless integration of services offered by different service providers which in addition can be located in different trust domains. Especially for business integration scenarios, Federated Identity Management emerged as a possibility to propagate identity information as security assertions across company borders in order to secure...

متن کامل

Federated Identification Architecture

Service Oriented Architectures are an abstract concept which exposes capabilities in distributed, domain-spanning environments as services. These modern systems have three characteristics: They are heterogeneous, distributed and loose Coupling. With increasing popularity of Service Oriented Architecture (SOA), this is no longer possible since interacting systems are generally not located within...

متن کامل

SPIKE1 – A Collaboration Platform for Short-Term Virtual Business Alliances

More and more companies are realising that business is best carried out in project-based virtual alliances and are intensively networking and collaborating with partner companies. This requires convergent, adaptive, and interoperable IT environments ready to support flexible, loosely coupled networked enterprises, anywhere, anytime regardless of heterogeneous systems and applications in use. Th...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008