Identity Management. Concepts, Technologies, and Systems
|
|
|
- Claud Clark
- 10 years ago
- Views:
Transcription
1 Identity Management Concepts, Technologies, and Systems
2 For a complete listing of titles in the Artech House Information Security and Privacy Series, turn to the back of this book.
3 Identity Management Concepts, Technologies, and Systems Elisa Bertino Kenji Takahashi
4 Library of Congress Cataloging-in-Publication Data A catalog record for this book is available from the U.S. Library of Congress. British Library Cataloguing in Publication Data A catalogue record for this book is available from the British Library. Cover design by Vicki Kane ISBN 13: ARTECH HOUSE 685 Canton Street Norwood, MA All rights reserved. Printed and bound in the United States of America. No part of this book may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying, recording, or by any information storage and retrieval system, without permission in writing from the publisher. All terms mentioned in this book that are known to be trademarks or service marks have been appropriately capitalized. Artech House cannot attest to the accuracy of this information. Use of a term in this book should not be regarded as affecting the validity of any trademark or service mark
5 Contents 1 Introduction Stakeholders and Business Opportunities Identity Ecosystem and Key Trends Challenges in Identity Management Overview of This Book 18 References 19 2 What Is Identity Management? Stakeholders and Their Requirements Subjects Identity Providers Relying Parties Control Parties Relationships Between Stakeholders Identity Life Cycle Creation Usage Update 34 5
6 6 Identity Management: Concepts, Technologies, and Systems Revocation Governance Identity Assurance 37 References 41 3 Fundamental Technologies and Processes Credentials Basic Concepts Public-Key Certificates and Public-Key Infrastructures Attribute and Authorization Certificates Credential Delegation Proxy Certificates Single Sign-On Kerberos Protocols Reverse Proxy-Based SSO Attribute Federation Distributed Mediation Single Party Based Mediation Privacy Pseudonym Systems Anonymous Credentials Assurance and Compliance 70 References 71 4 Standards and Systems Overview OASIS Security Assertion Markup Language (SAML) Overview Specification Structure Web SSO 86
7 Contents Use Cases Liberty Identity Web Services Framework Opt-In Discovery Registration Dynamic Acquisition of Consent from Subjects Federated Identity-Based Access Control Pseudonym Mapping Use Cases OpenID Overview Authentication Attribute Exchange (AX) Provider Authentication Policy Extension (PAPE) Simple Registration (SREG) Use Cases Information Card Based Identity Management (IC-IDM) Overview WS-MetadataExchange WS-Trust Use Cases Towards Interoperability Use Cases Comparative Analysis of SAML, OpenID, and Information Cards Security Analysis Confidentiality Integrity Availability Repudiation Authentication Authorization Privacy Analysis 130
8 8 Identity Management: Concepts, Technologies, and Systems 4.9 Research Prototypes SASSO VeryIDX SWIFT Emerging Areas: Social Networks, Mobile, and Cloud Computing 134 References Challenges Usability Usability Principles and Requirements Evaluating the Usability of Identity Management Solutions Antiphishing Measures Access Control Privacy Protection Privacy Policies Anonymization of Personally Identifiable Information and Privacy-Preserving Data Mining Privacy Protection in Emerging Services Trust Management Reputation of the Party Objective Verification of Certain Party Characteristics Possession of Credentials Attesting Certain Party Identity Information Trust in the Context of Identity Management Interoperability Challenge Universal User Experiences Naming Heterogeneity Management Biometrics 171 References 175
9 Contents 9 6 Conclusions 181 References 185 About the Authors 187 Index 189
10
11 1 Introduction Nowadays, a global information infrastructure the Web connects remote parties worldwide through the use of large scale networks, relying on application-level protocols and services, such as recent Web service technology. Enterprises are increasingly taking advantage of computing resources available on the Web through the use of cloud computing and virtualization technologies. Execution of activities in various domains and levels, such as shopping, entertainment, business and scientific collaboration, and social networking, is increasingly based on the use of remote resources and services, and on the interaction between different remotely located parties that may, and sometimes should, know little about each other. Thus, as the richness of our cyberspace lives begins to parallel our physical world experience, more convenient information and communication infrastructures and systems are expected. We expect, for example, that our personal preferences and profiles be readily available when shopping over the Web, without having to enter them repeatedly. In such a scenario, digital identity management technology is fundamental in customizing and enhancing the user experience, protecting privacy, underpinning accountability in transactions and interactions, and complying with regulatory controls. Digital identity can be defined as the digital representation of the information known about a specific individual or organization. Such information can be used for different purposes, ranging from allowing one to prove his or her claim to an identity (very much like the use of birth certificate or passport) to establishing permissions (like the use of a driver s license to establish the right to operate a vehicle). Digital identity may 11
12 12 Identity Management: Concepts, Technologies, and Systems include attributive information about an individual, such as a name, Social Security number (SSN), or passport number. Additionally, it may also incorporate biometric information, such as iris or fingerprint features, and information about user activities, including Web searches and e-shopping transactions. Digital identity may also encompass identifiers, like login names and pseudonyms, used by individuals when interacting with computer systems or with other individuals in the virtual world. 1.1 Stakeholders and Business Opportunities It is thus not a surprise that the development of tools, systems, and standards supporting an effective use and protection of digital identities is attracting great attention from individuals, enterprises, and governments. For individuals, identities are essential for enjoying interactive and personalized services, exemplified as Web 2.0, including social networks, blogs, virtual worlds, and wikis. Interactivity and personalization are two of the most important and distinctive characteristics of Web 2.0, comparing to Web 1.0, which aims to disseminate the information to the generic mass audience without identifying each recipient. Web 2.0 services are inevitably based on identities because it is impossible to interact, personalize, or socialize without identifying target parties. At the same time, consumers are starting to lose confidence in the security of the Internet because of many types of identity related problems, such as identity theft and privacy invasion. For example, the financial damage caused by identity theft was as much as $1.2 billion in 2007 in the United States alone [1]. Also people are proclaiming the erosion or death of privacy both in cyberspace and the real world in response to unexpected and undesirable leakage, dissemination, and/or abuse of personal information [2, 3]. Personal information is being collected, stored, analyzed, disseminated, and/or used on a massive scale, while in some cases the subjects of the information are not even aware that their data is being shared. On the other hand, business enterprises have already realized the huge opportunities offered by the use of identity data, for example, for personalized advertisement and service offerings. They have thus adopted open standard protocols for identity. For example, AOL, Facebook, France Telecom, Google, NTT, Yahoo!, and other major service providers in the world have recently adopted OpenID protocols [4]. The OpenID Foundation claims that there were 10 billion OpenID accounts worldwide in 2009 [5]. Also, as the world is becoming flat, enterprises globally collaborate across borders
13 Introduction 13 to pursue further agility and efficiency [6]. They access and use resources that are best fit to their needs no matter where the providers of the resources are located on the globe. Effective and efficient management of digital identities is needed for providers to identify customers (or vice versa) and control accesses to resources. In addition, enterprises are seeking identity and access management solutions as a basis for tighter security and governance measures required by regulations, such as the Sarbanes-Oxley Act in the United States. In response to market demands, major IT vendors, such as IBM, Microsoft, and Oracle, are lining up their product and service offerings for digital identity management. Also, open source projects for identity management, such as PHP OpenID Library [7], OpenSSO [8], SourceID [9], Bandits [10], and Higgins [11] are in progress. Governments play both roles as identity-enabled service providers and policy makers to regulate the use and protection of identities. As service providers, many countries are working on digital identity projects for their citizens and employees. National and local governments worldwide (e.g., Denmark, France, the United Kingdom, and the United States) have started adopting Security Assertion Markup Language (SAML), an international standard, to implement single sign-on 1 to a variety of online government services [12]. As policy makers, for example, the OECD has recognized the growing importance of digital identities and declared that to contribute to the development of the Internet Economy, we will strengthen confidence and security, through policies that ensure the protection of digital identities and personal data as well as the privacy of individuals online [13]. In 2009, the Obama administration released Cyberspace Policy Review, which recommends as a near-term action to build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties interests, leveraging privacy-enhancing technologies for the Nation [14]. Also international standardization organizations have started initiatives on identities. For example, the Internet Society has been conducting major strategic initiatives on trust and identity. It investigates the elevation of identity to a core issue in network research and standards development. The International Telecommunication Union (ITU) and ISO are also working on standardizations of identity management. Lastly, many research and development projects on identity are being actively pursued. For example, the European Union has funded several research and development projects on identity management, such as PrimeLife [15], SWIFT [16], and Future of Identity 1. A solution for simplifying login procedures (see Section 3.3).
14 14 Identity Management: Concepts, Technologies, and Systems in the Information Society (FDIS) [17]. The vision of FDIS expresses that, Europe will develop a deeper understanding of how appropriate identities and identity management can progress the way to a fair(er) European information society. 1.2 Identity Ecosystem and Key Trends The combination of individuals needs, business solutions, public policies, standards and technologies together is thus driving the formation of the identity ecosystem (Figure 1.1). The emerging ecosystem generates increasing interests in the management of digital identities in the information society. Thus, the identity management market is expected to rapidly grow. For example, the worldwide market is estimated to grow from $2.6 billion in 2006 to $12 billion in 2014 [18]. There are four key trends in the emerging ecosystem: Service orientation in shaping the identity ecosystem; Business restructuring; Figure 1.1 Identity ecosystem and key trends.
15 Introduction 15 Security and privacy; Compliance. Let us look at these trends. Service orientation means that society increasingly depends on services over networks. In providing services, digital identities play increasingly important roles. For example, solid digital identity bases are essential for implementing social welfare (e.g., healthcare and e-government), enabling secure service offering (e.g., cloud computing and software as a service), personalizing users experiences (e.g., e-commerce and entertainment), and connecting people over networks (e.g., social networking and mobile communications). Businesses, especially under the current drastic recession, are constantly being restructured with respect to their processes and organizations towards a higher level of profitability and agility. Business restructuring inevitably involves reorganizing the identity management of employees, partners, and customers. For example, the merger of two different companies requires the integration of the identities of employees, partners, and customers from both companies. Also the ever-changing markets demand businesses to collaborate with new partners in a short time, which requires identity systems to be able to interoperate across organizational borders. Security and privacy are universal problems, which require solid identity bases. Managing digital identity information raises a number of challenges due to conflicting requirements for security and privacy. On the one hand, this information needs to be shared to speed up and facilitate authentication of users and access control. On the other hand, it may convey sensitive information about an individual that needs to be protected against identity theft, wherein an attacker impersonates a victim by presenting stolen identifiers or proofs of identity. Identity theft can be perpetrated for different reasons, including: Financial reasons: Using another individual s identity to obtain services, goods, and financial resources; Criminal reasons: Posing as a different individual when apprehended for a crime; Identity cloning: Using the identity information of another individual to assume his or her identity.
16 16 Identity Management: Concepts, Technologies, and Systems Identity theft can have a severe impact on targeted individuals. In fact, the average monetary loss per victim attributed to the crime of identity theft is more than the amount attributed to bank robbery [19]. Additionally, handling the aftermath of the identity theft can be time-consuming, taking months to resolve. Using attacks such as password cracking, pharming, phishing, and database attacks, malicious parties can collect sensitive identity information of (targeted) individuals and use them to impersonate these individuals or just simply sell them. There are specific solutions to mitigate risks of each of these attacks [20]. Still, a systematic approach to protect digital identities thorough their life cycles is needed to mitigate risks of advanced attacks in the present and future. A paradox in the security and privacy of digital identity is that the most secure credentials can pose the greatest risk to an organization or individual. Using a cloned e-passport can certainly be much more harmful to the victim than using a stolen student ID issued by the victim s university. The problem results from an imbalance in the trust placed in digital identity credentials. As more security checks are used to verify the authenticity of an identity attribute, people are more likely to grant access to sensitive data when a forged credential is presented. That is, the amount of damage that can be done with a forged version of a weakly secure attribute is not comparable with that accomplished with an illicit copy of a highly secure attribute. Consequently, the payoff for a successful attack of a secure identity attribute can be far greater than for a weaker attribute. Legislation in various countries has brought a heightened awareness about privacy of individual identities and the problem of identity theft. For example, in the United States the problem of identity theft and the special status of an individual s SSN as an identifier in particular have been the focus of recent legislative activities. For instance, the Identity Theft and Assumption Deterrence Act of 1998 makes identity theft a federal crime [18 U.S.C (2003)]. Its purpose is to criminalize the act of identity theft itself, before other crimes are committed. Under this law, identity theft occurs when a person knowingly transfers, possesses or uses, without lawful authority, a means of identification of another person with the intent to commit, or to aid or abet, or in connection with, any unlawful activity that constitutes a violation of federal law, or that constitutes a felony under any applicable state or local law. Under this law, a name or SSN is considered a means of identification. Various states in the United States have attempted to be proactive with respect to the crime of identity theft as well. In Indiana, for example, a person who knowingly or intentionally obtains, possesses, transfers, or uses
17 Introduction 17 the identifying information of another person without consent and has an intent to harm or defraud another person or assume the other person s identity commits identity deception. Under Indiana s law, identifying information specifically includes an SSN. Growing recognition of the availability of the SSN and that number s ubiquitous use as a means of identifying a person for a number of purposes has spurred state legislation trying to combat the careless and cavalier use of the number. Currently Indiana is one of 33 states that have special legislation governing the use and exposure of personally identifying information, including the SSN. Many of the new laws enacted at the state level contain provisions addressing the circumstances under which an SSN and other personally identifying information can be disclosed to third parties, confidential destruction of papers and electronic media containing SSNs and personally identifying information of customers, and requirements for encryption of SSN and other sensitive personally identifying information held in electronically stored mediums. Complying with all these regulations and, at the same time, improving usability and user convenience and providing assurance about identity claims to service and resource providers, is challenging and requires flexible and rich digital identity management systems. Identity management also plays a key role in compliance to regulations related to corporate internal control and governance, such as the Sarbanes- Oxley Act and the Europe Data Protection Directive, and those targeted to vertical industries, such as the Gramm-Leach-Biley Act, Health Insurance Portability and Accountability Act, and Payment Card Industry Data Security Standard (PCI DSS). These regulations require enterprises to define thorough access policies to each piece of critical information (such as undisclosed business deals, trade secrets, and sensitive customer data) and enforce them while recording accountable audit trails. Implementing such a strict access control requires the adoption of solid identity management practices to authenticate and authorize only legitimate personnel for access to enterprise networks, computers, applications, and/or the critical data under certain conditions (e.g., privileges, time, place, and purposes). As the definition of a legitimate user expands, the challenge of identity and access management becomes more complex, and threats to the enterprise infrastructure increase. For enterprises, it is important to manage risks and to facilitate compliance with governmental and industry mandates. Superior identity management solutions can give enterprises the flexibility and integration to quickly adapt to changing market requirements and secure new initiatives and services. Furthermore, those regulations aim not only to prevent problems, but also
18 18 Identity Management: Concepts, Technologies, and Systems to promote the legitimate use of digital identities for the prosperity of the society. 1.3 Challenges in Identity Management Digital identity management must strike the best balance between usability, security, and privacy. A number of identity solutions are being proposed, each taking different approaches with different goals. Current solutions are not necessarily interoperable or complementary, and sometimes overlap. Thus it is critical to lay foundations for a holistic understanding of problem areas and synergetic approaches to innovative solutions, such as guidelines, methodologies, tools, and technical standards. Key questions to address towards identity management as an essential discipline for business and society include: How to make identities available only to the right individuals or services at the right time and place; How to establish trust between parties involved in identity transactions; How to avoid the abuse of identities; How to make these provisions possible in a scalable, usable, and costeffective manner. 1.4 Overview of This Book This book aims to give readers a comprehensive overview of digital identity management, from concepts to technologies and systems, to help them make better decisions in implementing identity management and foster further studies. In the following chapters, we will discuss the definition of identity management (Chapter 2), explain the fundamental concepts and techniques (Chapter 3), illustrate standards and technology landscapes (Chapter 4), analyze privacy issues (Chapter 5), explore challenges (Chapter 6), and conclude and present a future direction (Chapter 7).
19 Introduction 19 References [1] Federal Trade Commission, Consumer Fraud and Identity Theft Complaint Data, January December 2007, [2] Shaw, J., The Erosion of Privacy in the Internet Era, Harvard Magazine, September October 2009, pp [3] Garfinkel, S., Database Nation: The Death of Privacy in the 21st Century, New York: O Reilly Media, [4] OpenID, [5] OpenID Foundation, [6] Friedman, T. L., The World Is Flat, New York: Penguin Books, [7] OpenID PHP Library, [8] OpenSSO, [9] SourceID, [10] Project Bandit, [11] Project Higgins, [12] OASIS Security Services Technical Committee, Security Assertion Markup Language (SAML), [13] The Seoul Declaration for the Future of the Internet Economy, OECD, 2008, [14] Cyberspace Policy Review, 2009, Cyberspace_Policy_Review_final.pdf. [15] PrimeLife, [16] SWIFT, [17] Future of Identity in the Information Society, [18] Cserand, J., and A. Penn, Identity Management Market Forecast: 2007 to 2014, Forrester Research, [19] Analysis of Significant Identity Theft Trends & Crime Patterns in the State of New York, Identity Theft 911, 2004, [20] Goth, G., Identity Theft Solutions Disagree on Problem, IEEE Distributed Systems Online, Vol. 6, Issue 8, August 2005.
20
Identity Management. Concepts, Technologies, and Systems
Identity Management Concepts, Technologies, and Systems For a complete listing of titles in the Artech House Information Security and Privacy Series, turn to the back of this book. Identity Management
Nationwide and Regional Health Information Networks and Federated Identity for Authentication and HIPAA Compliance
Nationwide and Regional Health Information Networks and Federated Identity for Authentication and HIPAA Compliance Christina Stephan, MD Co-Chair Liberty Alliance ehealth SIG National Library of Medicine
Privacy in the Cloud A Microsoft Perspective
A Microsoft Perspective November 2010 The information contained in this document represents the current view of Microsoft Corp. on the issues discussed as of the date of publication. Because Microsoft
IDENTITY MANAGEMENT. February 2008. The Government of the Hong Kong Special Administrative Region
IDENTITY MANAGEMENT February 2008 The Government of the Hong Kong Special Administrative Region The contents of this document remain the property of, and may not be reproduced in whole or in part without
Fighting Identity Fraud with Data Mining. Groundbreaking means to prevent fraud in identity management solutions
Fighting Identity Fraud with Data Mining Groundbreaking means to prevent fraud in identity management solutions Contents Executive summary Executive summary 3 The impact of identity fraud? 4 The forgery
Solving for the Future: Addressing Major Societal Challenges Through Innovative Technology and Cloud Computing
Solving for the Future: Addressing Major Societal Challenges Through Innovative Technology and Cloud Computing As economic challenges persist in communities, nations, and regions around the world, the
Leveraging innovative security solutions for government. Helping to protect government IT infrastructure, meet compliance demands and reduce costs
IBM Global Technology Services Leveraging innovative security solutions for government. Helping to protect government IT infrastructure, meet compliance demands and reduce costs Achieving a secure government
Evaluation of different Open Source Identity management Systems
Evaluation of different Open Source Identity management Systems Ghasan Bhatti, Syed Yasir Imtiaz Linkoping s universitetet, Sweden [ghabh683, syeim642]@student.liu.se 1. Abstract Identity management systems
Understanding Enterprise Cloud Governance
Understanding Enterprise Cloud Governance Maintaining control while delivering the agility of cloud computing Most large enterprises have a hybrid or multi-cloud environment comprised of a combination
Preemptive security solutions for healthcare
Helping to secure critical healthcare infrastructure from internal and external IT threats, ensuring business continuity and supporting compliance requirements. Preemptive security solutions for healthcare
Biometrics and National Strategy for Trusted Identities in Cyberspace Improving the Security of the Identity Ecosystem September 19
Biometrics and National Strategy for Trusted Identities in Cyberspace Improving the Security of the Identity Ecosystem September 19 Andrew Sessions, Abel Sussman Biometrics Consortium Conference Agenda
RECOMMENDED CHARTER FOR THE IDENTITY ECOSYSTEM STEERING GROUP
RECOMMENDED CHARTER FOR THE IDENTITY ECOSYSTEM STEERING GROUP 1. Identity Ecosystem Steering Group Charter The National Strategy for Trusted Identities in Cyberspace (NSTIC or Strategy), signed by President
Glossary of Key Terms
and s Branch Glossary of Key Terms The terms and definitions listed in this glossary are used throughout the s Package to define key terms in the context of. Access Control Access The processes by which
The Top 5 Federated Single Sign-On Scenarios
The Top 5 Federated Single Sign-On Scenarios Table of Contents Executive Summary... 1 The Solution: Standards-Based Federation... 2 Service Provider Initiated SSO...3 Identity Provider Initiated SSO...3
Identity: The Key to the Future of Healthcare
Identity: The Key to the Future of Healthcare Chief Medical Officer Anakam Identity Services July 14, 2011 Why is Health Information Technology Critical? Avoids medical errors. Up to 98,000 avoidable hospital
CONNECTICUT IDENTITY THEFT RANKING BY STATE: Rank 19, 68.8 Complaints Per 100,000 Population, 2409 Complaints (2007) Updated November 28, 2008
CONNECTICUT IDENTITY THEFT RANKING BY STATE: Rank 19, 68.8 Complaints Per 100,000 Population, 2409 Complaints (2007) Updated November 28, 2008 Current Laws: A person commits identity theft when he intentionally
Achieving Universal Secure Identity Verification with Convenience and Personal Privacy A PRIVARIS BUSINESS WHITE PAPER
with Convenience and Personal Privacy version 0.2 Aug.18, 2007 WHITE PAPER CONTENT Introduction... 3 Identity verification and multi-factor authentication..... 4 Market adoption... 4 Making biometrics
WISCONSIN IDENTITY THEFT RANKING BY STATE: Rank 15, 175.9 Complaints Per 100,000 Population, 9852 Complaints (2007) Updated January 16, 2009
WISCONSIN IDENTITY THEFT RANKING BY STATE: Rank 15, 175.9 Complaints Per 100,000 Population, 9852 Complaints (2007) Updated January 16, 2009 Current Laws: It is unlawful to intentionally use or attempt
Application of Biometric Technology Solutions to Enhance Security
Application of Biometric Technology Solutions to Enhance Security Purpose: The purpose of this white paper is to summarize the various applications of fingerprint biometric technology to provide a higher
REGULATIONS FOR THE SECURITY OF INTERNET BANKING
REGULATIONS FOR THE SECURITY OF INTERNET BANKING PAYMENT SYSTEMS DEPARTMENT STATE BANK OF PAKISTAN Table of Contents PREFACE... 3 DEFINITIONS... 4 1. SCOPE OF THE REGULATIONS... 6 2. INTERNET BANKING SECURITY
IBM Security Privileged Identity Manager helps prevent insider threats
IBM Security Privileged Identity Manager helps prevent insider threats Securely provision, manage, automate and track privileged access to critical enterprise resources Highlights Centrally manage privileged
Biometrics in Identity as a Service
Daon - your trusted Identity Partner Biometrics in Identity as a Service What is BaaS and who is doing it? Catherine Tilton 28 September 2011 The Need As the world becomes more interdependent, as transactions
Feature. Log Management: A Pragmatic Approach to PCI DSS
Feature Prakhar Srivastava is a senior consultant with Infosys Technologies Ltd. and is part of the Infrastructure Transformation Services Group. Srivastava is a solutions-oriented IT professional who
Cybersecurity and Secure Authentication with SAP Single Sign-On
Solution in Detail SAP NetWeaver SAP Single Sign-On Cybersecurity and Secure Authentication with SAP Single Sign-On Table of Contents 3 Quick Facts 4 Remember One Password Only 6 Log In Once to Handle
National Cyber Security Policy -2013
National Cyber Security Policy -2013 Preamble 1. Cyberspace 1 is a complex environment consisting of interactions between people, software and services, supported by worldwide distribution of information
White paper December 2008. Addressing single sign-on inside, outside, and between organizations
White paper December 2008 Addressing single sign-on inside, outside, and between organizations Page 2 Contents 2 Overview 4 IBM Tivoli Unified Single Sign-On: Comprehensively addressing SSO 5 IBM Tivoli
On the Application of Trust and Reputation Management and User-centric Techniques for Identity Management Systems
On the Application of Trust and Reputation Management and User-centric Techniques for Identity Management Systems Ginés Dólera Tormo Security Group NEC Laboratories Europe Email: [email protected]
GLOBAL BUSINESS DIALOGUE ON ELECTRONIC COMMERCE CYBER SECURITY AND CYBER CRIME SEPTEMBER 26, 2000. CEO EDS Corporation
GLOBAL BUSINESS DIALOGUE ON ELECTRONIC COMMERCE CYBER SECURITY AND CYBER CRIME SEPTEMBER 26, 2000 Issue Chair: Issue Sherpa: Dick Brown CEO EDS Corporation Bill Poulos EDS Corporation Tel: (202) 637-6708
IT Privacy Certification Outline of the Body of Knowledge (BOK) for the Certified Information Privacy Technologist (CIPT)
Page 1 of 6 IT Privacy Certification Outline of the Body of Knowledge (BOK) for the Certified Information Privacy Technologist (CIPT) I. Understanding the need for privacy in the IT environment A. Evolving
Public Key Applications & Usage A Brief Insight
Public Key Applications & Usage A Brief Insight Scenario :: Identification, Authentication & Non- Repudiation :: Confidentiality :: Authenticity, requirements and e-business Integrity for electronic transaction
Top 5 Reasons to Choose User-Friendly Strong Authentication
SOLUTION BRIEF: USER-FRIENDLY STRONG AUTHENTICATION........................................ Top 5 Reasons to Choose User-Friendly Strong Authentication Who should read this paper This executive brief asserts
Opinion and recommendations on challenges raised by biometric developments
Opinion and recommendations on challenges raised by biometric developments Position paper for the Science and Technology Committee (House of Commons) Participation to the inquiry on Current and future
Secure Semantic Web Service Using SAML
Secure Semantic Web Service Using SAML JOO-YOUNG LEE and KI-YOUNG MOON Information Security Department Electronics and Telecommunications Research Institute 161 Gajeong-dong, Yuseong-gu, Daejeon KOREA
FIVE KEY CONSIDERATIONS FOR ENABLING PRIVACY IN HEALTH INFORMATION EXCHANGES
FIVE KEY CONSIDERATIONS FOR ENABLING PRIVACY IN HEALTH INFORMATION EXCHANGES The implications for privacy and security in the emergence of HIEs The emergence of health information exchanges (HIE) is widely
plantemoran.com What School Personnel Administrators Need to know
plantemoran.com Data Security and Privacy What School Personnel Administrators Need to know Tomorrow s Headline Let s hope not District posts confidential data online (Tech News, May 18, 2007) In one of
Securing the Healthcare Enterprise for Compliance with Cloud-based Identity Management
Securing the Healthcare Enterprise for Compliance with Cloud-based Identity Management Leveraging Common Resources and Investments to Achieve Premium Levels of Security Summary The ecosystem of traditional
Strengthen security with intelligent identity and access management
Strengthen security with intelligent identity and access management IBM Security solutions help safeguard user access, boost compliance and mitigate insider threats Highlights Enable business managers
Spotting ID Theft Red Flags A Guide for FACTA Compliance. An IDology, Inc. Whitepaper
Spotting ID Theft Red Flags A Guide for FACTA Compliance An IDology, Inc. Whitepaper With a November 1 st deadline looming for financial companies and creditors to comply with Sections 114 and 315 of the
PENNSYLVANIA IDENTITY THEFT RANKING BY STATE: Rank 14, 72.5 Complaints Per 100,000 Population, 9016 Complaints (2007) Updated January 29, 2009
PENNSYLVANIA IDENTITY THEFT RANKING BY STATE: Rank 14, 72.5 Complaints Per 100,000 Population, 9016 Complaints (2007) Updated January 29, 2009 Current Laws: A person commits the offense of identity theft
Oracle Identity Management for SAP in Heterogeneous IT Environments. An Oracle White Paper January 2007
Oracle Identity Management for SAP in Heterogeneous IT Environments An Oracle White Paper January 2007 Oracle Identity Management for SAP in Heterogeneous IT Environments Executive Overview... 3 Introduction...
White paper. Four Best Practices for Secure Web Access
White paper Four Best Practices for Secure Web Access What can be done to protect web access? The Web has created a wealth of new opportunities enabling organizations to reduce costs, increase efficiency
Provide access control with innovative solutions from IBM.
Security solutions To support your IT objectives Provide access control with innovative solutions from IBM. Highlights Help protect assets and information from unauthorized access and improve business
Good Afternoon! Since Yesterday we have been talking about threats and how to deal with those threats in order to protect ourselves from individuals
Good Afternoon! Since Yesterday we have been talking about threats and how to deal with those threats in order to protect ourselves from individuals and protect people, information, buildings, countries
Advanced Biometric Technology
INC Internet Biometric Security Systems Internet Biometric Security System,Inc.White Papers Advanced Biometric Technology THE SIMPLE SOLUTION FOR IMPROVING ONLINE SECURITY Biometric Superiority Over Traditional
WHITE PAPER Usher Mobile Identity Platform
WHITE PAPER Usher Mobile Identity Platform Security Architecture For more information, visit Usher.com [email protected] Toll Free (US ONLY): 1 888.656.4464 Direct Dial: 703.848.8710 Table of contents Introduction
Managing Trust in e-health with Federated Identity Management
ehealth Workshop Konolfingen (CH) Dec 4--5, 2007 Managing Trust in e-health with Federated Identity Management Dr. rer. nat. Hellmuth Broda Distinguished Director and CTO, Global Government Strategy, Sun
CONNECTING WITH CONFIDENCE: OPTIMISING AUSTRALIA S DIGITAL FUTURE. AIIA Response
CONNECTING WITH CONFIDENCE: OPTIMISING AUSTRALIA S DIGITAL FUTURE AIIA Response 14 November 2011 INTRODUCTION The Australian Information Industry Association (AIIA) is the peak national body representing
9. Information Assurance and Security, Protecting Information Resources. Janeela Maraj. Tutorial 9 21/11/2014 INFO 1500
INFO 1500 9. Information Assurance and Security, Protecting Information Resources 11. ecommerce and ebusiness Janeela Maraj Tutorial 9 21/11/2014 9. Information Assurance and Security, Protecting Information
OpenHRE Security Architecture. (DRAFT v0.5)
OpenHRE Security Architecture (DRAFT v0.5) Table of Contents Introduction -----------------------------------------------------------------------------------------------------------------------2 Assumptions----------------------------------------------------------------------------------------------------------------------2
MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE
WHITE PAPER MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE 1. OVERVIEW Do you want to design a file transfer process that is secure? Or one that is compliant? Of course, the answer is both. But it s
The Department of Health and Human Services Privacy Awareness Training. Fiscal Year 2015
The Department of Health and Human Services Privacy Awareness Training Fiscal Year 2015 Course Objectives At the end of the course, you will be able to: Define privacy and explain its importance. Identify
Cloud Computing. Chapter 5 Identity as a Service (IDaaS)
Cloud Computing Chapter 5 Identity as a Service (IDaaS) Learning Objectives Describe challenges related to ID management. Describe and discuss single sign-on (SSO) capabilities. List the advantages of
IDENTITY AND RESILIENCE
IDENTITY AND RESILIENCE Background With the advent of the era of the Internet and globalization, empowered individuals and groups have emerged who use global interconnectedness and anonymity to engage
The Anti-Corruption Compliance Platform
The Anti-Corruption Compliance Platform DATA COLLECTION RISK IDENTIFICATION SCREENING INTEGRITY DUE DILIGENCE CERTIFICATIONS GIFTS, TRAVEL AND ENTERTAINMENT TRACKING SECURITY AND DATA PROTECTION The ComplianceDesktop
DRAFT Pan Canadian Identity Management Steering Committee March 1, 2010
DRAFT Pan Canadian Identity Management Steering Committee March 1, 2010 Pan Canadian Identity Management & Authentication Framework Page 1 1 Introduction This document is intended to describe the forming
Indiana Social Security Number Disclosure and Security Breach Legislation
Indiana Social Security Number Disclosure and Security Breach Legislation Presented by: Joanna Lyn Grama, J.D., Information Security Project Manager Scott Ksander, Senior Inforensics Analyst/Engineer 1
OIO SAML Profile for Identity Tokens
> OIO SAML Profile for Identity Tokens Version 1.0 IT- & Telestyrelsen October 2009 Content > Document History 3 Introduction 4 Related profiles 4 Profile Requirements 6 Requirements 6
Digital Identity Management for Natural Persons
Please cite this paper as: OECD (2011), Digital Identity Management for Natural Persons: Enabling Innovation and Trust in the Internet Economy - Guidance for Government Policy Makers, OECD Digital Economy
Online Lead Generation: Data Security Best Practices
Online Lead Generation: Data Security Best Practices Released September 2009 The IAB Online Lead Generation Committee has developed these Best Practices. About the IAB Online Lead Generation Committee:
Federation Proxy for Cross Domain Identity Federation
Proxy for Cross Domain Identity Makoto Hatakeyama NEC Corporation, Common Platform Software Res. Lab. 1753, Shimonumabe, Nakahara-Ku, Kawasaki, Kanagawa 211-8666, Japan +81-44-431-7663 [email protected]
THE LEADING EDGE OF BORDER SECURITY
THE LEADING EDGE OF BORDER SECURITY RECORD-BREAKING TRAVEL CREATING NEW CHALLENGES TIM KLABUNDE Entrust Datacard; Director, Government Vertical Marketing THE ERA OF THE MOBILE IDENTITY In an increasingly
Beyond passwords: Protect the mobile enterprise with smarter security solutions
IBM Software Thought Leadership White Paper September 2013 Beyond passwords: Protect the mobile enterprise with smarter security solutions Prevent fraud and improve the user experience with an adaptive
How To Achieve Pca Compliance With Redhat Enterprise Linux
Achieving PCI Compliance with Red Hat Enterprise Linux June 2009 CONTENTS EXECUTIVE SUMMARY...2 OVERVIEW OF PCI...3 1.1. What is PCI DSS?... 3 1.2. Who is impacted by PCI?... 3 1.3. Requirements for achieving
addressed. Specifically, a multi-biometric cryptosystem based on the fuzzy commitment scheme, in which a crypto-biometric key is derived from
Preface In the last decade biometrics has emerged as a valuable means to automatically recognize people, on the base is of their either physiological or behavioral characteristics, due to several inherent
Case Study: SSO for All: SSOCircle Makes Single Sign-On Available to Everyone
Case Study: SSO for All: SSOCircle Makes Single Sign-On Available to Everyone Although single sign-on (SSO) technology based on Liberty standards is being rapidly adopted by businesses, governments and
COLORADO IDENTITY THEFT RANKING BY STATE: Rank 8, 89.0 Complaints Per 100,000 Population, 4328 Complaints (2007) Updated November 28, 2008
COLORADO IDENTITY THEFT RANKING BY STATE: Rank 8, 89.0 Complaints Per 100,000 Population, 4328 Complaints (2007) Updated November 28, 2008 Current Laws: A person commits identity theft if he or she: Knowingly
Stay ahead of insiderthreats with predictive,intelligent security
Stay ahead of insiderthreats with predictive,intelligent security Sarah Cucuz [email protected] IBM Security White Paper Executive Summary Stay ahead of insider threats with predictive, intelligent
Cloud-based Identity and Access Control for Diagnostic Imaging Systems
Cloud-based Identity and Access Control for Diagnostic Imaging Systems Weina Ma and Kamran Sartipi Department of Electrical, Computer and Software Engineering University of Ontario Institute of Technology
Attribute-Based Access Control Solutions: Federating Authoritative User Data to Support Relying Party Authorization Decisions and Requirements
Joint White Paper: Attribute-Based Access Control Solutions: Federating Authoritative User Data to Support Relying Party Authorization Decisions and Requirements Submitted Date: April 10, 2013 Submitted
A NEW APPROACH TO CYBER SECURITY
A NEW APPROACH TO CYBER SECURITY We believe cyber security should be about what you can do not what you can t. DRIVEN BY BUSINESS ASPIRATIONS We work with you to move your business forward. Positively
Signicat white paper. Signicat Solutions. This document introduces the Signicat solutions for digital identities and electronic signatures 2015-08
Signicat white paper Signicat Solutions This document introduces the Signicat solutions for digital identities and electronic signatures 2015-08 Version 1.1 2015-08-20 Disclaimer Please note that this
THE CHANGING FACE OF IDENTITY THEFT THE CURRENT AND FUTURE LANDSCAPE
THE CHANGING FACE OF IDENTITY THEFT THE CURRENT AND FUTURE LANDSCAPE Identity is the unique set of characteristics that define an entity or individual. Identity theft is the unauthorized use of an individual
Compliance and Industry Regulations
Compliance and Industry Regulations Table of Contents Introduction...1 Executive Summary...1 General Federal Regulations and Oversight Agencies...1 Agency or Industry Specific Regulations...2 Hierarchy
Defending the Internet of Things
Defending the Internet of Things Identity at the Core of Security +1-888-690-2424 entrust.com Table of contents Introduction Page 3 Challenge: protecting & managing identity Page 4 Founders of identity
INFORMATION TECHNOLOGY POLICY
COMMONWEALTH OF PENNSYLVANIA DEPARTMENT OF PUBLIC WELFARE INFORMATION TECHNOLOGY POLICY Name Of : DPW Information Security and Privacy Policies Domain: Security Date Issued: 05/09/2011 Date Revised: 11/07/2013
COMMUNIQUÉ ON PRINCIPLES FOR INTERNET POLICY-MAKING OECD HIGH LEVEL MEETING ON THE INTERNET ECONOMY,
COMMUNIQUÉ ON PRINCIPLES FOR INTERNET POLICY-MAKING OECD HIGH LEVEL MEETING ON THE INTERNET ECONOMY, 28-29 JUNE 2011 The Seoul Declaration on the Future of the Internet Economy adopted at the 2008 OECD
Information Security Basic Concepts
Information Security Basic Concepts 1 What is security in general Security is about protecting assets from damage or harm Focuses on all types of assets Example: your body, possessions, the environment,
Federated Identity Management Solutions
Federated Identity Management Solutions Jyri Kallela Helsinki University of Technology [email protected] Abstract Federated identity management allows users to access multiple services based on a single
ESET Secure Authentication
ESET Secure Authentication Second factor authentication and compliance Document Version 1.2 6 November, 2013 www.eset.com ESET Secure Authentication - second factor authentication and compliance 2 2 Summary
