Evaluation of Unified Security, Trust and Privacy Framework (UnifiedSTPF) for Federated Identity and Access Management (FIAM) Mode

International Journal of Computer Applications
© 2012 by IJCA Journal
Volume 54 - Number 6
Year of Publication: 2012
Zubair Ahmad Khattak
Suziah Sulaiman
Jamalul-lail Ab. Manan

Zubair Ahmad Khattak, Suziah Sulaiman and Jamalul-lail Ab. Manan. Article: Evaluation of Unified Security, Trust and Privacy Framework (UnifiedSTPF) for Federated Identity and Access Management (FIAM) Mode. International Journal of Computer Applications 54(6):12-19, September 2012. Full text available. BibTeX

	author = {Zubair Ahmad Khattak and Suziah Sulaiman and Jamalul-lail Ab. Manan},
	title = {Article: Evaluation of Unified Security, Trust and Privacy Framework (UnifiedSTPF) for Federated Identity and Access Management (FIAM) Mode},
	journal = {International Journal of Computer Applications},
	year = {2012},
	volume = {54},
	number = {6},
	pages = {12-19},
	month = {September},
	note = {Full text available}


Federated identity and access management systems such as Shibboleth may symbolize a boost: (i) to bring the efficiency and effectiveness in collaboration for governments, enterprises and academia, and (iii) conserve the home domain user's identity privacy in a privacy-enhanced fashion. However, the consternation is about the absence of a trusted computing based mutual trust and security establishment in the Shibboleth infrastructure. The Trusted Computing based mutual attestation notion may assist to add-on the mutual trust and security but raises bidirectional platform privacy concerns. Therefore, to enjoy effectively the federated identity and resource (service) access by the home and foreign domain organizations it is necessary to provide an access control that may coalesced at least some security, trust and privacy aspects in a cohesive fashion. The objective of the work appearing in this paper is to provide a viable and feasible unified security, trust and privacy framework access control solution for federated identity and access management systems by fusing the Shibboleth authentication and authorization access control with the trusted computing based trustworthy mutual attestation.


