Département Réseau, Sécurité et Multimédia Rapport d'Activités 2008

Département Réseau, Sécurité et Multimédia Rapport d'Activités 2008

Département Réseau, Sécurité et Multimédia Rapport d'Activités 2008


Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Protekto, the OrBAC model and the XACMLstandard will be used.Delegation of this security functions is asolution that reduces costs and increasessecurity, moreover users will take advantage ofthe last technological advancements insecurity. The content provider’s work will befacilitated with only the contents productionand the users will appreciate the single sign onand the identity management.RealisationThe first part of the project is aboutauthentication, researches about how tointegrate OpenID and SAML tog<strong>et</strong>her in theplatform were performed. SAML 2.0 is anadvanced solution for exchanging securityinformation but is also more complex thanOpenID. As for OpenID, the number of usersand sites is growing and potential usersnumber is more than 350 millions, this recentprotocol is very interesting for users with themanaging of their identity.We made an OpenID identity provider (usingthe version 2.0 of OpenID), allowing users tocreate their identity, manage attributes withprofiles and information sent to sites they visit,and personalized their OpenID identity page.Interaction b<strong>et</strong>ween users was also a concern,users can manage a buddy list and sendmessages to friends registered on this identityprovider. Moreover in order to ease the use ofour provider, efforts were made for theinterface and two different implementations inXHTML and flash were developed.Protekto is also an OpenID consumer, andthen users registered to another OpenIDprovider are able to use our platform. AsOpenID is a fully decentralized system, wewere able to validate our work with differentOpenID enabled sites on the Intern<strong>et</strong>.Regarding security requirement, OpenID is aweak form of authentication, and then it is notappropriate for sensitive transactions likeelectronic payment. SAML 2.0 is more securefor these operations, it permits assertionsabout authorization and can be used with theXACML standard. But it is less practical for theuser who needs to be registered to a providerbelonging to the circle of trust. That is why ourplatform uses these two protocols, OpenIDvery interesting for users and SAML moresecure for providers with sensitive contents.We began an authentication server using SAMLwith an OpenID consumer part. We l<strong>et</strong> userschoose if they want to be authenticated usingtheir OpenID identity (from our OpenIDidentity provider but also from otherproviders). After authentication, informationare exchanged using SAML 2.0 and if anOpenID identity is used then a specific SAML2.0 authentication context for OpenID isneeded.A registration of Protekto at the Agency forProtection of Programs (APP) was made byNora Boulahia-Cuppens, Frédéric Cuppens,François Wang (Télécom Br<strong>et</strong>agne), andStéphane Morucci (SWID).Future workFuture work will consist in addingfunctionalities to our OpenID identity provider,and finishing to integrate SAML 2.0 to theProtekto platform. Then the second partconcerning authorization, the XACML profilewill be added for access control. TélécomBr<strong>et</strong>agne work on the OrBAC model will bevalued thanks to their tools they developedwhich adapt OrBAC policies to XACML.Reference[1] Assertions and Protocols for the OASISSAML V2.0. OASIS SSTC, March 2005.Pracom’s Annual Report <strong>2008</strong> 39

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!