Trait-based Authorization Mechanisms for SIP Based on SAML
نویسندگان
چکیده
This paper presents a method for using the Security Assertion Markup Language (SAML) in collaboration with SIP to accommodate richer authorization mechanisms and enable trait-based authorization whereby users are authorized based on traits (or attributes) instead of identity. As such, this provides an alternative to existing authorization mechanisms for SIP. Existing mechanisms are generally identity based and present challenges in face of frequent changing identities, pseudonyms or even privacy enabling environments. Such a trait-based authorization mechanism has significant applicability to SIP. There are numerous instances in which it is valuable to assert particular facts about a principal other than the principal's identity to aid the recipient of a request in making an authorization policy decision. For example, a telephony service provider might assert that a particular user is a 'customer' as a trait. An emergency services network might indicate that a particular user has a privileged status as a caller. Although trait-based authorization offers an alternative to traditional identity based authorization, this effort should be considered complementary to sophisticated SIP security mechanisms available today.
منابع مشابه
Internet - Draft SIP SAML November 2007
This document specifies a Session Initiation Protocol (SIP) profile of Security Assertion Markup Language (SAML) as well as a SAML SIP binding. The defined SIP SAML Profile composes with the mechanisms defined in the SIP Identity specification and satisfy requirements presented in "Trait-based Authorization Requirements for the Session Initiation Protocol (SIP)". Table of
متن کاملInternet - Draft SIP SAML
This document specifies a Session Initiation Protocol (SIP) profile of Security Assertion Markup Language (SAML) as well as a SAML SIP binding. The defined SIP SAML Profile composes with the mechanisms defined in the SIP Identity specification and satisfy requirements presented in "Trait-based Authorization Requirements for the Session Initiation Protocol (SIP)". Table of
متن کاملInternet - Draft SIP SAML July 2008
This document specifies a Session Initiation Protocol (SIP) profile of Security Assertion Markup Language (SAML) as well as a SAML SIP binding. The defined SIP SAML Profile composes with the mechanisms defined in the SIP Identity specification and satisfy requirements presented in "Trait-based Authorization Requirements for the Session Initiation Protocol (SIP)". Tschofenig, et al. Expires Janu...
متن کاملIntended status : Experimental J . Hodges Expires : September 9 , 2009 Unaffiliated
This document specifies a Session Initiation Protocol (SIP) profile of Security Assertion Markup Language (SAML) as well as a SAML SIP binding. The defined SIP SAML Profile composes with the mechanisms defined in the SIP Identity specification and satisfy requirements presented in "Trait-based Authorization Requirements for the Session Initiation Protocol (SIP)". Tschofenig, et al. Expires Sept...
متن کاملInternet - Draft Using SAML for SIP
Using SAML for SIP draft-tschofenig-sip-saml-02.txt Status of this Memo This document is an Internet-Draft and is subject to all provisions of section 3 of RFC 3667. By submitting this Internet-Draft, each author represents that any applicable patent or other IPR claims of which he or she is aware have been or will be disclosed, and any of which he or she become aware will be disclosed, in acco...
متن کامل