Committed to connecting the world

  •  
wtisd

ITU-T work programme

[2013-2016] : [SG17] : [Q10/17]

[Declared patent(s)]  - [Publication]

Work item: X.1258 (ex X.eaaa)
Subject/title: Enhanced entity authentication based on aggregated attributes
Status: Approved on 2016-09-07 
Approval process: TAP
Type of work item: Recommendation
Version: New
Equivalent number: -
Timing: -
Liaison: -
Supporting members: China Unicom, China Unicom, ETRI, KISA, Korea (Rep. Of), MBNA, Uganda.
Summary: Aggregating attributes from multiple attribute authorities may be needed in order to enable a relying party to enhance its trust in the identity of a party. The aggregation can be regarded as having to deal with a collection of globally unique identifiers, which is common across all attribute authorities. Practically, entities do not have a global identifier but have different entity identifiers and attributes assigned by their various identity service providers (IdSPs). To address the attribute aggregating problem in this scenario, the concept of identity federation is used. For example, if an e-book store plans to have a sale for seniors, the store has to be given the aggregated set of attributes (credit card and age bracket) from two IdSPs, but without the IdSPs knowing about each other's involvement. In standard federated identity management, an entity can only provide attributes from one identity, but this transaction requires attributes from two. There are several identity federation methods such as security assertion markup language (SAML), Shibboleth [b-Shibboleth], open identity (OpenID), and open authentication (OAuth), etc. Recommendation ITU-T X.1258 introduces the concept of attribute aggregation to allow an entity to aggregate attributes from multiple IdSPs. Attribute aggregation is the mechanism of collecting attributes of an entity retrieved from multiple identity service providers. Attribute aggregation is needed to aggregate the attributes dynamically on demand. IdSP can realize the aggregation request when an entity wants to get a service. Further on, an entity-centric attribute aggregation mechanism could also be applied to the authentication for mitigating privacy leakage.
Comment: this work item is in cooperation with Q7/17
Reference(s):
[R 64 ]
  Historic references:
Contact(s):
Tae-Kyung Kim, Editor
Jae Hoon Nah, Editor
Junjie Xia, Editor
ITU-T A.5 justification(s):
Generate A.5 drat TD
-
[Submit new A.5 justification ]
See guidelines for creating & submitting ITU-T A.5 justifications
First registration in the WP: 2014-10-22 15:16:21
Last update: 2016-09-29 16:14:01