2014
DOI: 10.1007/978-3-642-55415-5_25
|View full text |Cite
|
Sign up to set email alerts
|

Géant-TrustBroker: Dynamic, Scalable Management of SAML-Based Inter-federation Authentication and Authorization Infrastructures

Abstract: Part 7: Identity ManagementInternational audienceWe present the concept and design of Géant-TrustBroker, a new service to facilitate multi-tenant ICT service user authentication and authorization (AuthNZ) management in large-scale eScience infrastructures that is researched and implemented by the pan-European research and education network, Géant. Géant-TrustBroker complements eduGAIN, a successful umbrella inter-federation created on top of national higher education federations in more than 20 countries world… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2

Citation Types

0
5
0

Year Published

2016
2016
2020
2020

Publication Types

Select...
3
1

Relationship

3
1

Authors

Journals

citations
Cited by 4 publications
(5 citation statements)
references
References 1 publication
(1 reference statement)
0
5
0
Order By: Relevance
“…Other approaches focus on federation as a service, which utilizes cloud infrastructure. The framework AIDF by Zouari and Hamdi [88] makes use of a trust broker, like in [58]…”
Section: Federated Identity Management As a Servicementioning
confidence: 99%
See 1 more Smart Citation
“…Other approaches focus on federation as a service, which utilizes cloud infrastructure. The framework AIDF by Zouari and Hamdi [88] makes use of a trust broker, like in [58]…”
Section: Federated Identity Management As a Servicementioning
confidence: 99%
“…Furthermore, the division into trusted, semi-trusted, and untrusted is rather coarsegrained [REQ6], and a further database per entity is needed [REQ11]. Another approach is called TrustBroker by Pöhn et al[58], which is based on SAML, though the generic concepts can be applied to FIM[REQ3]. There are also other federation approaches.…”
mentioning
confidence: 99%
“…These characteristics are very important for the interoperability between security technologies of different administrative domains to be accomplished. According to [151,178,179], the first step toward achieving interoperability is the adoption of SAML. However, XML-based SAML is not a lightweight standard and has a high computational cost for IoT resource-constrained devices [176].…”
Section: Federated Identity Management Systemmentioning
confidence: 99%
“…Since more and more services are offered on-demand, the practical problem and relevant question is, if the SAML metadata, required to make use of FIM, can be exchanged securely on-demand. This article adds security considerations and a risk management based on a template to the GÉANT-TrustBroker approach (Pöhn et al, 2014). The new approach, initiated by the eduGAIN operators (GÉANT project), needs to be as secure as FIM with SAML can be, even though new components and workflows are introduced.…”
Section: Introductionmentioning
confidence: 99%
“…By that, if IDP and SP technically do not know each other, the TTP triggers the metadata exchange on-demand. This approach is also described in (Pöhn et al, 2014), where the state of the art, basic concepts, workflows, and database design were explained. As only the necessary metadata is exchanged, this significantly improves the scalability of the metadata exchange, while at the same time avoids performance bottlenecks.…”
Section: Introductionmentioning
confidence: 99%