Trust requirements in identity management

Audun Jøsang, John W. Fabre, Brian Hay, James Dalziel, Simon Pope

2005 · 148 citations · 2 references

Concepts

TL;DR

Identity management involves representing and verifying digital identities, underpinning authentication, authorization, and access control, and its models vary in trust requirements, making simpler trust models desirable due to associated costs. The paper aims to describe trust problems in current identity management approaches. It proposes solutions to address these trust problems.

Abstract

Identity management refers to the process of representing and recognising entities as digital identities in computer networks. Authentication, which is an integral part of identity management, serves to verify claims about holding specific identities. Identity management is therefore fundamental to, and sometimes include, other security constructs such as authorisation and access control. Different identity management models will have different trust requirements. Since there are costs associated with establishing trust, it will be an advantage to have identity management models with simple trust requirements. The purpose of this paper is to describe trust problems in current approaches to identity management, and to propose some solutions.

References

2