Direkt zum Inhalt

Schläger, Christian ; Sojer, Manuel ; Muschall, Björn ; Pernul, Günther

Attribute-Based Authentication and Authorisation Infrastructures for E-Commerce Providers

Schläger, Christian, Sojer, Manuel, Muschall, Björn und Pernul, Günther (2006) Attribute-Based Authentication and Authorisation Infrastructures for E-Commerce Providers. In: Bauknecht, Kurt, (ed.) E-Commerce and Web Technologies: 7th International Conference, EC-Web 2006, Krakow, Poland, 05.-07 September 2006; proceedings. Lecture Notes in Computer Science, 4082. Springer, Heidelberg, S. 132-141. ISBN 978-3-540-37743-6.

Veröffentlichungsdatum dieses Volltextes: 05 Aug 2009 13:23
Buchkapitel


Zusammenfassung

Authentication and authorisation has been a basic and necessary service for internet transactions. With the evolution of e-commerce, traditional mechanisms for data security and access control are becoming outdated. Several new standards have emerged which allow dynamic access control based on exchanging user attributes. Unfortunately, while providing highly secure and flexible access mechanisms ...

Authentication and authorisation has been a basic and necessary service for internet transactions. With the evolution of e-commerce, traditional mechanisms for data security and access control are becoming outdated. Several new standards have emerged which allow dynamic access control based on exchanging user attributes. Unfortunately, while providing highly secure and flexible access mechanisms is a very demanding task, it cannot be considered a core competency for most e-commerce corporations. Therefore, a need to outsource or at least share such services with other entities arises. Authen-tication and Authorisation Infrastructures (AAIs) can provide such integrated federations of security services. They could, in particular, provide attribute-based access control (ABAC) mechanisms and mediate customers’ demand for privacy and vendors’ needs for information. We propose an AAI reference model that includes ABAC functionality based on the XACML standard and lessons learned from various existing AAIs. AAIs analysed are AKENTI, CARDEA, CAS, GridShib, Liberty ID-FF, Microsoft .NET Passport, PAPI, PERMIS, Shibboleth and VOMS.



Beteiligte Einrichtungen


Details

DokumentenartBuchkapitel
ISBN978-3-540-37743-6
Buchtitel:E-Commerce and Web Technologies: 7th International Conference, EC-Web 2006, Krakow, Poland, 05.-07 September 2006; proceedings
Verlag:Springer
Ort der Veröffentlichung:Heidelberg
Sonstige Reihe:Lecture Notes in Computer Science
Band:4082
Seitenbereich:S. 132-141
Datum2006
InstitutionenWirtschaftswissenschaften > Institut für Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Informatik und Data Science > Fachbereich Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Identifikationsnummer
WertTyp
10.1007/11823865DOI
Dewey-Dezimal-Klassifikation300 Sozialwissenschaften > 330 Wirtschaft
StatusVeröffentlicht
BegutachtetJa, diese Version wurde begutachtet
An der Universität Regensburg entstandenJa
Dokumenten-ID427

Bibliographische Daten exportieren

Nur für Besitzer und Autoren: Kontrollseite des Eintrags

nach oben