Privacy Protected Authentication and Authorisation
Facebook Twitter LinkedIn

Privacy Protected Authentication and Authorisation

Combined Session
Thursday, May 12, 2011 16:30—17:30
Location: Alpsee

CardSpace in the Cloud describes a web based federated identity management system which is based on the user centric approach of the Information Card model, but has been significantly enhanced to remove many of the problems inherent in Microsoft’s original design. The new design is an alternative to UProve and Idemix credentials, and uses existing SAML 2 federations and assertions. Our model supports privacy protection of the user attributes, user mobility and the aggregation of multiple claims from different identity providers (IdPs), whilst only requiring the user to authenticate via just one of his IdPs. Furthermore no constraints are placed on the authentication mechanism that is used by this IdP. The level of assurance (LoA) of the authenticating IdP is built into the design.

All this is achieved by introducing a new component, the Linking Identity Selector, which can run anywhere in the cloud, and allows the user to select multiple cards at service provision time. Users can then use the combined set of credentials to access a wider range of web based resources. We describe a use case which allows the user to present a credit card, a self asserted card, a hotel loyalty card and a frequent flyer card in order to make an online hotel booking, using voice biometrics for authentication.

Ronny Bjones
Ronny Bjones
Microsoft
Ronny Bjones currently is working for Microsoft Corporate as senior architect in the identity & security division. Ronny joined Microsoft in 2002 to contribute in trustworthy computing. Later...
Dr. David Chadwick
Dr. David Chadwick
University of Kent / Verifiable Credentials Ltd.
Prof David Chadwick has been working in identity management for over 20 years and has written over a 100 papers on the topic. He was the chief architect and designer of the PERMIS open source...
Dr. Gregory Neven
Dr. Gregory Neven
IBM Research - Zurich
Gregory Neven is a research scientist at IBM Research - Zurich in Switzerland. His main research topics are provably secure cryptography and privacy policy languages, in which fields he has...
Subscribe for updates
Please provide your email address