Choice of suitable Identity and Access Management standards for mobile computing and communication

Nitin Naik*, Paul Jenkins, David Newell

*Awdur cyfatebol y gwaith hwn

Allbwn ymchwil: Pennod mewn Llyfr/Adroddiad/Trafodion CynhadleddCyfraniad mewn cynhadleddadolygiad gan gymheiriaid

14 Dyfyniadau (Scopus)

Crynodeb

Enterprises have recognised the importance of personal mobile devices for business and official use. Employees and consumers have been freely accessing resources and services from their principal organisation and partners' businesses on their mobile devices, to improve the efficiency and productivity of their businesses. This mobile computing-based business model has one major challenge, that of ascertaining and linking users' identities and access rights across business partners. The parent organisation owns all the confidential information about users but the collaborative organisation has to verify users' identities and access rights to allow access to their services and resources. This challenge involves resolving how to communicate users' identities to collaborative organisations without sending their confidential information. Several generic Identity and Access Management (IAM) standards have been proposed, and three have become established standards: Security Assertion Markup Language (SAML), Open Authentication (OAuth), and OpenID Connect (OIDC). Mobile computing and communication have some specific requirements and limitations; therefore, this paper evaluates these IAM standards to ascertain suitable IAM to protect mobile computing and communication. This evaluation is based on the three types of analyses: Comparative analysis, suitability analysis and security vulnerability analysis of SAML, OAuth and OIDC.

Iaith wreiddiolSaesneg
TeitlProceedings of the 24th International Conference on Telecommunications
Is-deitlIntelligence in Every Form, ICT 2017
GolygyddionHamid Aghvami, Christos Verikoukis, Georgios Ellinas, Vasos Vassiliou, George Kamel, Paolo Bellavista, Panayiotis Kolios, Symeon Chatzinotas
CyhoeddwrInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronig)9781538606421
Dynodwyr Gwrthrych Digidol (DOIs)
StatwsCyhoeddwyd - 3 Awst 2017
Cyhoeddwyd yn allanolIe
Digwyddiad24th International Conference on Telecommunications, ICT 2017 - Limassol, Cyprus
Hyd: 3 Mai 20175 Mai 2017

Cyfres gyhoeddiadau

EnwProceedings of the 24th International Conference on Telecommunications: Intelligence in Every Form, ICT 2017

Cynhadledd

Cynhadledd24th International Conference on Telecommunications, ICT 2017
Gwlad/TiriogaethCyprus
DinasLimassol
Cyfnod3/05/175/05/17

Dyfynnu hyn