E-government and cloud: Security implementation for services
Alessandro Bettacchi, Barbara Re, Alberto Polzonetti · 2017
Public Administration sector in modern society is characterized by the need to simplify and streamline how to provide services to citizens and business. The enactment of e-government services has been a valuable solution that, thanks to cloud computing, has also ensured greater efficiency, effectiveness, transparency and interoperability. However, such approach creates new challenges for security and trust. In this scenario the paper describes a security framework that implements a centralized access control, providing authentication and authorization to a wide range of Web applications and services delivered by Public Administration and deployed in the cloud. Authentication occurs according to the SSO federated pattern that assumes the use of remote Identity Providers for login. To this end we decided to leverage the Public Digital Identity System (SPID), a security infrastructure that ensures to citizens and enterprises to be uniquely recognized. Federation is realized according to SPID specifications which rely on the SAML standard, while the interaction between the security framework and the applications/services to be protected is mainly enforced via the OAuth2/OpenID Connect protocol, but, to ensure a smooth transition of existing applications to the cloud, additional proprietary methods have been taken into account.