Click here for full text:
On Identity Assurance in the Presence of Federated Identity Management Systems
Baldwin, Adrian; Casassa Mont, Marco; Shiu, Simon
Keyword(s): identity; assurance; identity assurance; trust; federation
Abstract: In this paper we address the appropriate management of risk in federated identity management systems by presenting an identity assurance framework and supporting technologies. We start by discussing the risk mitigation framework that should be part of any identity assurance solution. We then demonstrate how our model based assurance technologies can be used to report success of an identity assurance programme. We discuss how this approach can be used to gain trust within a federated identity management solution both by communicating the nature of the assurance framework and that risks are successfully being mitigated. Finally, we show the importance of automation of controls in easing operational costs; providing improved audit information and changing the risk mitigation landscape.
Back to Index