Several countries have invested in building their identity management systems to equip citizens with infrastructures and tools to benefit from e-services. However, current systems still lack the interoperability requirement, which is the core issue that could lower the wide benefits of having an identity management system. In fact, in the existing systems, the user is allowed to choose only one partial identity from an identity provider (IdP) during a single session with a service provider (SP). However, in some scenarios, an SP needs to retrieve information about user’s identities managed by multiple IdPs. The potential method to tackle these shortcomings is attribute aggregation from multiple identity providers. A number of initiatives and projects on attribute aggregation have been explored. Nevertheless, these constructions do not fulfill some identity management requirements. This paper describes a new flexible model that aims to provide the necessary mechanisms to ensure attribute aggregation in order to meet the interoperability challenges of current identity management systems. The proposed scheme is a scalable solution, based on identity federation technologies, that introduces a new IdP called an account linking provider (ALP). The purpose of this ALP is to link together different accounts, holding end users’ attributes, whenever more than one source of data is needed to grant access to the requested web resource in a single session. Furthermore, the proposed identity federation system is based on a streamlined, cost-effective, and interoperable architecture, which makes this model suitable for large-scale identity federation environments.
[1]
Bart De Decker,et al.
User-centric identity management using trusted modules
,
2013,
Math. Comput. Model..
[2]
Antonio F. Gómez-Skarmeta,et al.
A SWIFT Take on Identity Management
,
2009,
Computer.
[3]
Moshe Zviran,et al.
Identification and Authentication: Technology and Implementation Issues
,
2006,
Commun. Assoc. Inf. Syst..
[4]
David W. Chadwick,et al.
A conceptual model for attribute aggregation
,
2010,
Future Gener. Comput. Syst..
[5]
Yongge Wang,et al.
Security analysis of a password-based authentication protocol proposed to IEEE 1363
,
2006,
Theor. Comput. Sci..
[6]
George Roussos,et al.
Mobile Identity Management: An Enacted View
,
2003,
Int. J. Electron. Commer..
[7]
Antonio F. Gómez-Skarmeta,et al.
Formal description of the SWIFT identity management framework
,
2011,
Future Gener. Comput. Syst..