Universal Identity Management Model Based on Anonymous Credentials
Yang Zhang, Junliang Chen · 2010
The relationship-focused and credential-focused identity management are both user-centric notions in Service-oriented architecture (SOA). For composite services, pure user-centric identity management is inefficient because each sub-service may authenticate and authorize users and users need participate in every identity provisioning transaction. If the above two paradigms are unified into the universal identity management model where identity information and privileges are delegatable, user-centricity will be more feasible in SOA. This paper aims to extend WS-Federation to build a universal identity management model based on anonymous credentials, which provides the delegation of anonymous credentials and combines identity metasystem to support easy-to-use, consistent experience and transparent security. In addition, the concept of self-generated pseudonym is introduced to construct efficient anonymous delegation model.