信息安全研究 ›› 2019, Vol. 5 ›› Issue (10): 929-934.

• 数字认证专辑 • 上一篇    下一篇

身份管理系统身份联合互操作能力研究

张严,张立武   

  1. 中国科学院软件研究所可信计算与信息保障实验室
  • 收稿日期:2019-10-08 出版日期:2019-10-15 发布日期:2019-10-08
  • 通讯作者: 张严
  • 作者简介:张严,男,1987年生,博士学位,中国科学院软件研究所 高级工程师,主要研究领域为网络空间安全、鉴别授权,E-mail: zhangyan@tca.iscas.ac.cn 张立武,男,1976年生,博士学位,中国科学院软件研究所 正高级工程师/博士生导师,主要研究领域为网络空间安全、计算机视觉、人工智能,E-mail: liwu@iscas.ac.cn

Research on Identity Federation Interoperability of Identity Management Systems

  • Received:2019-10-08 Online:2019-10-15 Published:2019-10-08

摘要: 随着电子认证2.0时代的到来,身份管理边界不断演变,并逐渐被打破,通过身份联合方案实现身份管理服务间的互联互通已成为当前网络应用的主要模式,涌现了包括安全断言置标语言(SAML),OpenID,OAuth,FIDO等在内的一系列身份联合方案和标准.在我国访问量最高的网站和使用量最大的移动APP中,大部分均提供身份联合服务或支持通过其他应用的账号进行用户登录.但是,目前的身份联合相关实现均与特定的单一身份联合方案相绑定,也缺乏不同身份联合方案间的互操作参考.为了解决这一问题,首先对现有身份联合方案与标准进行了分析,总结了身份管理系统在进行身份联合操作时可以实现的不同功能作为身份管理系统的身份联合互操作能力,之后针对这些能力,给出了身份管理系统应为实现这些能力而必须达到的功能与安全要求,最后,以OpenID标准为例,给出了所提出的身份联合能力要求在实际身份联合过程中的应用方法,验证了相关要求的可用性.

关键词: 身份管理, 身份联合, 互操作, 网络安全, 鉴别, 授权

Abstract: With the advent of the era of electronic authentication 2.0, the boundaries of identity management have evolved and been gradually broken, and the interconnection between identity management services through the identity federation frame has become the main mode of current network applications. A range of identity federation schemes and standards such as SAML, OpenID, OAuth, FIDO have emerged. Most of the highest visited websites and the most used mobile APPs in China provide identity federation services or support for to login through accounts of other applications. However, the current identity federationrelated implementations are bound to a specific single identity federation scheme, and there is no mutual reference between different identity federation schemes. In order to solve this problem, first of all, the existing identity federation scheme and standards are analyzed, and the different functions that identity management system can achieve when performing identity federation operation are proposed as the identity federation interoperability capability of identity management system; Then, for these capabilities, the function and security requirements that identity management system should have possessed and realizedand , and finally, taking the OpenID as an example, the application method of the proposed requirement in the actual identity federation process is given, which verified the availability of relevant requirements.

Key words: identity management, identity federation, cooperation, network security, authentication, authorization