Privacy Preserving Identity Federation: A Literature Study

Anne Bumiller, Elisavet Kozyri, Håvard Dagenborg · ACM Computing Surveys · 2025

Within an Identity federation (IF) system, users gain access to multiple Service Provider s (SPs) by submitting credentials issued by one or more Identity Provider s (IdPs). Such Identity Federations (IFs) raise several privacy concerns: IdPs might track user activity, by recording the accessed services, and SPs might mismanage sensitive user attributes that comprise the submitted credentials. An extensive line of research on Privacy Preserving IF has been developed to expose and address these privacy concerns. This survey aims to systematize the privacy requirements and enhancement techniques that has been employed so far in this line of research. Specifically, we use Systematic Mapping Study (SMS) and Systematic Literature Review (SLR) methodologies to organize research work from the last ten years and understand (i) the requirements that privacy-preserving IF is expected to satisfy, (ii) the degree at which these requirements have been formalized, (iii) the techniques employed to enforce these requirements, (iv) the means for providing enforcement assurance, and (v) the degree at which these techniques preserve fundamental authentication objectives and are aligned with existing IF standards. Based on this characterization of the literature, we draw conclusions about the rigorousness of the proposed approaches, their deployability into practice, and lessons learned for future research and practice in the field.

Read the paper · More papers on PaperTik