Making identity assurance and authentication strength work for federated infrastructures

Ziegler, J. A.; Stevanovic, U.; Groep, D.; Neilson, I.; Kelsey, D. P.; Kremers, M.


In both higher Research and Education (R&E) as well as in research-/ e-infrastructures (in short: infrastructures), federated access and single sign-on by way of national federations, operated in most cases by NRENs, are used as a means to provide users with access to a variety of services. Whereas in national federations institutional accounts, e.g. provided by a university, are typically used to access services, many infrastructures also accept other sources of identity: provided by ''community identity providers'', social identity providers, or governmental IDs. In order to assess and communicate the quality of identities being used and authentications being performed, so called Level of Assurance (LoA) frameworks are used. Because sophisticated LoA frameworks like NIST 800-63-3, Kantara IAF 1420 or eIDAS regulation are often considered too complex to be used in R&E scenarios, the REFEDS Assurance Suite, a more lightweight approach, has been developed. To select an appropriate assurance level, Service Providers need to weigh risks and potential harms in relation to the kind of service they offer. However, the management of risks is often implicitly assumed and little or no guidance to determine the appropriate assurance level is given. ... mehr

DOI: 10.5445/IR/1000140364
Veröffentlicht am 29.11.2021
Zugehörige Institution(en) am KIT Institut für Prozessdatenverarbeitung und Elektronik (IPE)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2021
Sprache Englisch
Identifikator ISSN: 1824-8039
KITopen-ID: 1000140364
Erschienen in International Symposium on Grids & Clouds 2021, ISGC2021: 22-26 March, 2021 ; Academia Sinica, Taipei, Taiwan (online). Ed.: K. Aida
Veranstaltung International Symposium on Grids & Clouds (2021), Online, 22.03.2021 – 26.03.2021
Verlag Scuola Internazionale Superiore di Studi Avanzati (SISSA)
Seiten Art.-Nr.: 029
Serie Proceedings of Science ; 378
Nachgewiesen in Dimensions
