Adaptive security architectural model for protecting identity federation in service oriented computing

With the tremendous growth of Internet and its related technologies, the Service Oriented Architecture (SOA) became a dominant paradigm shift for enterprise computing. In SOA, business functionalities are offered by many different Service Providers as services. In order to get served by different se...

Full description

Bibliographic Details
Main Authors: Mohamed Ibrahim Beer Mohamed, Mohd Fadzil Hassan, Sohail Safdar, Muhammad Qaiser Saleem
Format: Article
Language:English
Published: Elsevier 2021-06-01
Series:Journal of King Saud University: Computer and Information Sciences
Subjects:
SSO
SOA
EAI
Online Access:http://www.sciencedirect.com/science/article/pii/S1319157818310590
id doaj-7b217e61990548ca8e38972a0e01179f
record_format Article
spelling doaj-7b217e61990548ca8e38972a0e01179f2021-06-03T04:55:59ZengElsevierJournal of King Saud University: Computer and Information Sciences1319-15782021-06-01335580592Adaptive security architectural model for protecting identity federation in service oriented computingMohamed Ibrahim Beer Mohamed0Mohd Fadzil Hassan1Sohail Safdar2Muhammad Qaiser Saleem3Department of Computer & Information Sciences, Universiti Teknologi PETRONAS, 32610 Seri Iskandar, Perak Darul Ridzuan, Malaysia; Corresponding author at: B-06-3A Millennium Square, Jalan 14/1, Seksyen 14, 46100 Petaling Jaya, Malaysia.Center for Research in Data Science (CeRDaS), Universiti Teknologi PETRONAS, 32610 Seri Iskandar, Perak Darul Ridzuan, Malaysia.Department of Information Technology, College of Information Technology, Ahlia University, Manama, BahrainCollege of Computer Science and Information Technology, Al Baha University, Al Baha, Saudi ArabiaWith the tremendous growth of Internet and its related technologies, the Service Oriented Architecture (SOA) became a dominant paradigm shift for enterprise computing. In SOA, business functionalities are offered by many different Service Providers as services. In order to get served by different service providers, the client has to authenticate with those service providers at multiple times. Single Sign On (SSO) mechanism provides the client to login only one time so that access to different services is made possible without needing to re-authenticate. Here, the identity of the logged-in client is federated among the enterprise computing nodes. This is one of the simplest forms of federated identity. The goal of identity federation is to benefit ease of use, flexibility, productivity and reduced cost of the authentication process, but trust and security is a major concern in this situation. Major threats on federated identity management are due to identity misuse, identity theft, and trust deficit between identity providers and services providers. As of now, the Security Assertion Markup Language (SAML), Open Authorization (OAuth) and OpenID are the three important federated identity management standards in the industry. However, none of them is equipped by itself to provide comprehensive security protection for identity federation even within a single enterprise computing environment. In fact, these federated solutions result in additional security vulnerabilities due to their openness of identity federation. The security threats are becoming severe when federated identity is spanned into the inter-organizational and intra-organizational computing environment. This paper analyses the vulnerabilities and security gaps in the existing federated identity solutions. To overcome these gaps, an adaptive security architectural model is proposed for identity federation at inter and intra-organizational level using public key infrastructure that adheres to the SOA security standards and specifications. The proposed architecture is implemented and tested in a large-scale federated identity enterprise computing environment with security-centric financial data to acquire the desired results. A cross-sectional comparative analysis is done between existing and proposed solutions to validate the improvement in the protection of identity federation environment.http://www.sciencedirect.com/science/article/pii/S1319157818310590Federated identitySSOSecuritySOAEAITrust
collection DOAJ
language English
format Article
sources DOAJ
author Mohamed Ibrahim Beer Mohamed
Mohd Fadzil Hassan
Sohail Safdar
Muhammad Qaiser Saleem
spellingShingle Mohamed Ibrahim Beer Mohamed
Mohd Fadzil Hassan
Sohail Safdar
Muhammad Qaiser Saleem
Adaptive security architectural model for protecting identity federation in service oriented computing
Journal of King Saud University: Computer and Information Sciences
Federated identity
SSO
Security
SOA
EAI
Trust
author_facet Mohamed Ibrahim Beer Mohamed
Mohd Fadzil Hassan
Sohail Safdar
Muhammad Qaiser Saleem
author_sort Mohamed Ibrahim Beer Mohamed
title Adaptive security architectural model for protecting identity federation in service oriented computing
title_short Adaptive security architectural model for protecting identity federation in service oriented computing
title_full Adaptive security architectural model for protecting identity federation in service oriented computing
title_fullStr Adaptive security architectural model for protecting identity federation in service oriented computing
title_full_unstemmed Adaptive security architectural model for protecting identity federation in service oriented computing
title_sort adaptive security architectural model for protecting identity federation in service oriented computing
publisher Elsevier
series Journal of King Saud University: Computer and Information Sciences
issn 1319-1578
publishDate 2021-06-01
description With the tremendous growth of Internet and its related technologies, the Service Oriented Architecture (SOA) became a dominant paradigm shift for enterprise computing. In SOA, business functionalities are offered by many different Service Providers as services. In order to get served by different service providers, the client has to authenticate with those service providers at multiple times. Single Sign On (SSO) mechanism provides the client to login only one time so that access to different services is made possible without needing to re-authenticate. Here, the identity of the logged-in client is federated among the enterprise computing nodes. This is one of the simplest forms of federated identity. The goal of identity federation is to benefit ease of use, flexibility, productivity and reduced cost of the authentication process, but trust and security is a major concern in this situation. Major threats on federated identity management are due to identity misuse, identity theft, and trust deficit between identity providers and services providers. As of now, the Security Assertion Markup Language (SAML), Open Authorization (OAuth) and OpenID are the three important federated identity management standards in the industry. However, none of them is equipped by itself to provide comprehensive security protection for identity federation even within a single enterprise computing environment. In fact, these federated solutions result in additional security vulnerabilities due to their openness of identity federation. The security threats are becoming severe when federated identity is spanned into the inter-organizational and intra-organizational computing environment. This paper analyses the vulnerabilities and security gaps in the existing federated identity solutions. To overcome these gaps, an adaptive security architectural model is proposed for identity federation at inter and intra-organizational level using public key infrastructure that adheres to the SOA security standards and specifications. The proposed architecture is implemented and tested in a large-scale federated identity enterprise computing environment with security-centric financial data to acquire the desired results. A cross-sectional comparative analysis is done between existing and proposed solutions to validate the improvement in the protection of identity federation environment.
topic Federated identity
SSO
Security
SOA
EAI
Trust
url http://www.sciencedirect.com/science/article/pii/S1319157818310590
work_keys_str_mv AT mohamedibrahimbeermohamed adaptivesecurityarchitecturalmodelforprotectingidentityfederationinserviceorientedcomputing
AT mohdfadzilhassan adaptivesecurityarchitecturalmodelforprotectingidentityfederationinserviceorientedcomputing
AT sohailsafdar adaptivesecurityarchitecturalmodelforprotectingidentityfederationinserviceorientedcomputing
AT muhammadqaisersaleem adaptivesecurityarchitecturalmodelforprotectingidentityfederationinserviceorientedcomputing
_version_ 1721399839725453312