Abstract | ||
---|---|---|
In this paper we address the appropriate management of risk in federated identity management systems by presenting an identity assurance framework and supporting technologies. We start by discussing the risk mitigation framework that should be part of any identity assurance solution. We then demonstrate how our model based assurance technologies can be used to report success of an identity assurance programme. We discuss how this approach can be used to gain trust within a federated identity management solution both by communicating the nature of the assurance framework and that risks are successfully being mitigated. Finally, we show the importance of automation of controls in easing operational costs (and we describe related approaches developed at HP Labs and PRIME project); providing improved audit information and changing the risk mitigation landscape. |
Year | DOI | Venue |
---|---|---|
2007 | 10.1145/1314403.1314409 | Digital Identity Management |
Keywords | Field | DocType |
federated identity management system,federated identity management solution,risk mitigation framework,identity assurance solution,identity assurance programme,risk mitigation landscape,assurance technology,identity assurance framework,appropriate management,assurance framework,control,audit,risk mitigation,risk | Internet privacy,Audit,Computer science,Knowledge management,Automation,Identity management,Program assurance,Risk management,Operational costs,Federated identity management,Process management | Conference |
Citations | PageRank | References |
2 | 0.59 | 2 |
Authors | ||
4 |
Name | Order | Citations | PageRank |
---|---|---|---|
Yolanta Beres | 1 | 47 | 6.21 |
Adrian Baldwin | 2 | 149 | 20.92 |
Marco Casassa Mont | 3 | 289 | 33.03 |
Simon Shiu | 4 | 109 | 16.59 |