Adaptive security architectural model for protecting identity federation in service oriented computing
With the tremendous growth of Internet and its related technologies, the Service Oriented Architecture (SOA) became a dominant paradigm shift for enterprise computing. In SOA, business functionalities are offered by many different Service Providers as services. In order to get served by different se...
Main Authors: | , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Elsevier
2021-06-01
|
Series: | Journal of King Saud University: Computer and Information Sciences |
Subjects: | |
Online Access: | http://www.sciencedirect.com/science/article/pii/S1319157818310590 |
id |
doaj-7b217e61990548ca8e38972a0e01179f |
---|---|
record_format |
Article |
spelling |
doaj-7b217e61990548ca8e38972a0e01179f2021-06-03T04:55:59ZengElsevierJournal of King Saud University: Computer and Information Sciences1319-15782021-06-01335580592Adaptive security architectural model for protecting identity federation in service oriented computingMohamed Ibrahim Beer Mohamed0Mohd Fadzil Hassan1Sohail Safdar2Muhammad Qaiser Saleem3Department of Computer & Information Sciences, Universiti Teknologi PETRONAS, 32610 Seri Iskandar, Perak Darul Ridzuan, Malaysia; Corresponding author at: B-06-3A Millennium Square, Jalan 14/1, Seksyen 14, 46100 Petaling Jaya, Malaysia.Center for Research in Data Science (CeRDaS), Universiti Teknologi PETRONAS, 32610 Seri Iskandar, Perak Darul Ridzuan, Malaysia.Department of Information Technology, College of Information Technology, Ahlia University, Manama, BahrainCollege of Computer Science and Information Technology, Al Baha University, Al Baha, Saudi ArabiaWith the tremendous growth of Internet and its related technologies, the Service Oriented Architecture (SOA) became a dominant paradigm shift for enterprise computing. In SOA, business functionalities are offered by many different Service Providers as services. In order to get served by different service providers, the client has to authenticate with those service providers at multiple times. Single Sign On (SSO) mechanism provides the client to login only one time so that access to different services is made possible without needing to re-authenticate. Here, the identity of the logged-in client is federated among the enterprise computing nodes. This is one of the simplest forms of federated identity. The goal of identity federation is to benefit ease of use, flexibility, productivity and reduced cost of the authentication process, but trust and security is a major concern in this situation. Major threats on federated identity management are due to identity misuse, identity theft, and trust deficit between identity providers and services providers. As of now, the Security Assertion Markup Language (SAML), Open Authorization (OAuth) and OpenID are the three important federated identity management standards in the industry. However, none of them is equipped by itself to provide comprehensive security protection for identity federation even within a single enterprise computing environment. In fact, these federated solutions result in additional security vulnerabilities due to their openness of identity federation. The security threats are becoming severe when federated identity is spanned into the inter-organizational and intra-organizational computing environment. This paper analyses the vulnerabilities and security gaps in the existing federated identity solutions. To overcome these gaps, an adaptive security architectural model is proposed for identity federation at inter and intra-organizational level using public key infrastructure that adheres to the SOA security standards and specifications. The proposed architecture is implemented and tested in a large-scale federated identity enterprise computing environment with security-centric financial data to acquire the desired results. A cross-sectional comparative analysis is done between existing and proposed solutions to validate the improvement in the protection of identity federation environment.http://www.sciencedirect.com/science/article/pii/S1319157818310590Federated identitySSOSecuritySOAEAITrust |
collection |
DOAJ |
language |
English |
format |
Article |
sources |
DOAJ |
author |
Mohamed Ibrahim Beer Mohamed Mohd Fadzil Hassan Sohail Safdar Muhammad Qaiser Saleem |
spellingShingle |
Mohamed Ibrahim Beer Mohamed Mohd Fadzil Hassan Sohail Safdar Muhammad Qaiser Saleem Adaptive security architectural model for protecting identity federation in service oriented computing Journal of King Saud University: Computer and Information Sciences Federated identity SSO Security SOA EAI Trust |
author_facet |
Mohamed Ibrahim Beer Mohamed Mohd Fadzil Hassan Sohail Safdar Muhammad Qaiser Saleem |
author_sort |
Mohamed Ibrahim Beer Mohamed |
title |
Adaptive security architectural model for protecting identity federation in service oriented computing |
title_short |
Adaptive security architectural model for protecting identity federation in service oriented computing |
title_full |
Adaptive security architectural model for protecting identity federation in service oriented computing |
title_fullStr |
Adaptive security architectural model for protecting identity federation in service oriented computing |
title_full_unstemmed |
Adaptive security architectural model for protecting identity federation in service oriented computing |
title_sort |
adaptive security architectural model for protecting identity federation in service oriented computing |
publisher |
Elsevier |
series |
Journal of King Saud University: Computer and Information Sciences |
issn |
1319-1578 |
publishDate |
2021-06-01 |
description |
With the tremendous growth of Internet and its related technologies, the Service Oriented Architecture (SOA) became a dominant paradigm shift for enterprise computing. In SOA, business functionalities are offered by many different Service Providers as services. In order to get served by different service providers, the client has to authenticate with those service providers at multiple times. Single Sign On (SSO) mechanism provides the client to login only one time so that access to different services is made possible without needing to re-authenticate. Here, the identity of the logged-in client is federated among the enterprise computing nodes. This is one of the simplest forms of federated identity. The goal of identity federation is to benefit ease of use, flexibility, productivity and reduced cost of the authentication process, but trust and security is a major concern in this situation. Major threats on federated identity management are due to identity misuse, identity theft, and trust deficit between identity providers and services providers. As of now, the Security Assertion Markup Language (SAML), Open Authorization (OAuth) and OpenID are the three important federated identity management standards in the industry. However, none of them is equipped by itself to provide comprehensive security protection for identity federation even within a single enterprise computing environment. In fact, these federated solutions result in additional security vulnerabilities due to their openness of identity federation. The security threats are becoming severe when federated identity is spanned into the inter-organizational and intra-organizational computing environment. This paper analyses the vulnerabilities and security gaps in the existing federated identity solutions. To overcome these gaps, an adaptive security architectural model is proposed for identity federation at inter and intra-organizational level using public key infrastructure that adheres to the SOA security standards and specifications. The proposed architecture is implemented and tested in a large-scale federated identity enterprise computing environment with security-centric financial data to acquire the desired results. A cross-sectional comparative analysis is done between existing and proposed solutions to validate the improvement in the protection of identity federation environment. |
topic |
Federated identity SSO Security SOA EAI Trust |
url |
http://www.sciencedirect.com/science/article/pii/S1319157818310590 |
work_keys_str_mv |
AT mohamedibrahimbeermohamed adaptivesecurityarchitecturalmodelforprotectingidentityfederationinserviceorientedcomputing AT mohdfadzilhassan adaptivesecurityarchitecturalmodelforprotectingidentityfederationinserviceorientedcomputing AT sohailsafdar adaptivesecurityarchitecturalmodelforprotectingidentityfederationinserviceorientedcomputing AT muhammadqaisersaleem adaptivesecurityarchitecturalmodelforprotectingidentityfederationinserviceorientedcomputing |
_version_ |
1721399839725453312 |