論文

査読有り
2014年1月1日

Privacy preserving attribute aggregation method without shared identifier binding

Journal of Information Processing
  • Takeshi Nishimura
  • ,
  • Motonori Nakamura
  • ,
  • Kazutsuna Yamaji
  • ,
  • Hiroyuki Sato
  • ,
  • Yasuo Okabe

22
3
開始ページ
472
終了ページ
479
記述言語
英語
掲載種別
研究論文(学術雑誌)
DOI
10.2197/ipsjjip.22.472
出版者・発行元
Information Processing Society of Japan

Identity federation is rapidly spreading, especially in the academic world. In identity federation users' credentials are stored only at their own organization, while the identity system provides authentication results and attributes to various online services, including cloud services that are hosted outside the user's organization. Attribute aggregation is a generalization of basic identity federation that allows a user to collect attributes from multiple authoritative sources. Group membership information is one of use cases, which is necessary to collaborate e.g., in an inter-organizational group. Despite the importance of privacy in identity federation, conventional methods of attribute aggregation require some identifier for a user to be shared among unrelated services, which makes correlation of user activity possible across the services. This privacy issue makes large-scale deployment of collaboration environments built on identity federation difficult. This paper proposes a new attribute aggregation method which does not require any shared identifier for services. The method has been implemented and validated as an extension of an open source federated identity software, Shibboleth. We also provide consideration about practical use of this new attribute aggregation method and comparison with existing technologies. © 2014 Information Processing Society of Japan.

リンク情報
DOI
https://doi.org/10.2197/ipsjjip.22.472
ID情報
  • DOI : 10.2197/ipsjjip.22.472
  • ISSN : 1882-6652
  • ISSN : 0387-5806
  • SCOPUS ID : 84904299060

エクスポート
BibTeX RIS