|
Title:
|
AUTHORIZATION OF USER PROFILE ACCESS IN IDENTITY MANAGEMENT |
|
Author(s):
|
Wolfgang Woerndl |
|
ISBN:
|
972-99353-0-0 |
|
Editors:
|
Pedro IsaĆas and Nitya Karmakar |
|
Year:
|
2004 |
|
Edition:
|
1 |
|
Keywords:
|
Authorization, user profile, identity management, access control, privacy. |
|
Type:
|
Full Paper |
|
First Page:
|
309 |
|
Last Page:
|
316 |
|
Language:
|
English |
|
Cover:
|
|
|
Full Contents:
|
click to dowload
|
|
Paper Abstract:
|
Distributed management of user profiles and identities allow reuse of profile information for different personalization services but also raises privacy issues. Users need a possibility to control access to their personal information in a sophisticated, yet flexible way. Our approach divides the authorization of user profile access into two phases: first a negotiation of access rights based on privacy policies and preferences, and second the actual access of profile information. The core of the proposed solution is a so-called Access Ticket, which specifies the access rights of a particular service to parts of a user profile. The approach combines access control mechanisms and privacy enhancing technologies, in addition with new concepts such as identity levels. |
|
|
|
|
|
|