Federated Identity-Management Protocols

  • Birgit Pfitzmann
  • Michael Waidner
Part of the Lecture Notes in Computer Science book series (LNCS, volume 3364)


For authentication, one answer to the workshop question “where have all the protocols gone?” is “into federated identity management”. At least this is what many influential industrial players are currently striving for. The best-known examples are Microsoft Passport, the Liberty Alliance’s proposals, and WS-Federation. While there have been many political discussions about Passport, in particular its privacy, and some technical studies of operational risks, there is almost no public literature about the actual protocols and their security.

We start with an overview of the driving factors in this space, the security properties desirable and achievable under the given design constraints, and the protocols proposed so far. We present a new protocol, BBAE, with better privacy and scalability, i.e., absence of single points of control, than prior proposals. We also discuss particular difficulties of rigorously treating a protocol that can be a profile in current standardization efforts.


Privacy Policy User Agent Secure Channel Security Assertion Markup Language Destination Site 
These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.


Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.


  1. 1.
    Abadi, M., Needham, R.: Prudent Engineering Practice for Cryptographic Protocols. IEEE Transactions on Software Engineering 22/1, 6–15 (1996)CrossRefGoogle Scholar
  2. 2.
    Anderson, R., Needham, R.: Robustness principles for public key protocols. In: Coppersmith, D. (ed.) CRYPTO 1995. LNCS, vol. 963, pp. 236–247. Springer, Heidelberg (1995)Google Scholar
  3. 3.
    Bohrer, K., Liu, X., Kesdogan, D., Schonberg, E., Singh, M., Spraragen, S.: Personal Information Management and Distribution. In: 4th Intern. Conf. on Electronic Commerce Research (ICECR-4), Dallas (2001)Google Scholar
  4. 4.
    Chaum, D.: Security without Identification: Transaction Systems to make Big Brother Obsolete. Communications of the ACM 28/10, 1030–1044 (1985)CrossRefGoogle Scholar
  5. 5.
    Camenisch, J., Van Herreweghen, E.: Design and Implementation of the Idemix Anonymous Credential System. In: 9th ACM Conference on Computer and Communications Security (CCS), pp. 21–30 (2002)Google Scholar
  6. 6.
    Groß, T.: Security Analysis of the SAML Single Sign-on Browser/Artifact Profile. In: 19th Annual Computer Security Applications Conference (ACSAC 2003). IEEE Computer Society Press, Los Alamitos (2003)Google Scholar
  7. 7.
    IBM Consumer Wallet; White Paper, 1999 (first release 1997), http://www-3.ibm.com/software/webservers/commerce/payment/wallet.pdf
  8. 8.
    IBM: Enterprise Security Architecture using IBM Tivoli Security Solutions (April 2002), http://www.redbooks.ibm.com/abstracts/sg246014.html
  9. 9.
    Kormann, D.P., Rubin, A.D.: Risks of the Passport Single Signon Protocol. Computer Networks 33, 51–58 (2000)CrossRefGoogle Scholar
  10. 10.
    Liberty Alliance Project: Liberty Phase 2 Final Specifications (November 2003), http://www.projectliberty.org/specs/lap-phase2-final.zip (v1.0 July 2002)
  11. 11.
    Microsoft Corporation: .NET Passport documentation, in particular Technical Overview, September 2001 and SDK 2.1 Documentation (started 1999), http://www.passport.com and, http://msdn.microsoft.com/downloads
  12. 12.
    Passlogix: v-Go Single Signon; White Paper (2000), http://www.passlogix.com/media/pdfs/usable_security.pdf (first release 1999)
  13. 13.
    Pfitzmann, B., Waidner, M.: BBAE – A General Protocol for Browser-based Attribute Exchange; IBM Research Report RZ 3455 (#93800) 09/09/02, http://www.zurich.ibm.com/security/publications/2002/
  14. 14.
    Pfitzmann, B., Waidner, M.: Privacy in Browser-Based Attribute Exchange. In: ACM Workshop on Privacy in the Electronic Society (WPES) 2002, pp. 52–62. ACM Press, New York (2003)Google Scholar
  15. 15.
    Pfitzmann, B., Waidner, M.: Analysis of Liberty Single-Signon with Enabled Clients. IEEE Internet Computing 7(6), 38–44 (2003)CrossRefGoogle Scholar
  16. 16.
    Roboform: Free Web Form Filler and Password Manager (first release 1999), http://www.siber.com/roboform/
  17. 17.
    Security Assertion Markup Language (SAML). OASIS Standard (November 2002), http://www.oasis-open.org/committees/security/docs/
  18. 18.
    Shibboleth-Architecture Draft v05 (May 2002), http://middleware.internet2.edu/shibboleth/docs/draft-internet2-shibboleth-arch-v05.pdf (v01 in 2001)
  19. 19.
    Slemko, M.: Microsoft Passport to Trouble. Rev. 1.18 (November 2001), http://alive.znep.com/~marcs/passport/
  20. 20.
    BEA, IBM, Microsoft, RSA Security, VeriSign: WS-Federation: Passive Requestor Profile. Draft, Version 1.0 (July 2003), http://www-106.ibm.com/developerworks/webservices/
  21. 21.
    HTTP Over TLS; Internet RFC 2818 (2000)Google Scholar
  22. 22.
    XML-Signature Syntax and Processing; W3C Recommendation (February 2002), http://www.w3.org/TR/xmldsig-core/
  23. 23.
    Zeroknowledge: Freedom Personal Firewall (first release 1999), http://www.freedom.net/products/firewall/index.html

Copyright information

© Springer-Verlag Berlin Heidelberg 2005

Authors and Affiliations

  • Birgit Pfitzmann
    • 1
  • Michael Waidner
    • 1
  1. 1.IBM Zurich Research Lab 

Personalised recommendations