ETSI GS INS 006-2011 Identity and access management for Networks and Services Study to Identify the need for a Global Distributed Discovery Mechanism《网络和业务的身份和接入管理 确定全球性分布式发现机制需求的研_1.pdf
《ETSI GS INS 006-2011 Identity and access management for Networks and Services Study to Identify the need for a Global Distributed Discovery Mechanism《网络和业务的身份和接入管理 确定全球性分布式发现机制需求的研_1.pdf》由会员分享,可在线阅读,更多相关《ETSI GS INS 006-2011 Identity and access management for Networks and Services Study to Identify the need for a Global Distributed Discovery Mechanism《网络和业务的身份和接入管理 确定全球性分布式发现机制需求的研_1.pdf(20页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI GS INS 006 V1.1.1 (2011-11) Identity and access management for Networks and Services; Study to Identify the need for a Global, Distributed Discovery Mechanism Disclaimer This document has been produced and approved by the Identity and access management for Networks and Services (INS) ETSI Indu
2、stry Specification Group (ISG) and represents the views of those members who participated in this ISG. It does not necessarily represent the views of the entire ETSI membership. Group Specification ETSI ETSI GS INS 006 V1.1.1 (2011-11) 2Reference DGS/INS-006 Keywords access, control, ID, management,
3、 network, service ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice Individual copies of the pres
4、ent document can be downloaded from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF). In case
5、of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and
6、other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced except as authorized
7、 by written permission. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2011. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM a
8、nd LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI GS INS 006 V1.1.1 (2011-11) 3Contents Intellectual Property Rights 4g3Foreword . 4g3Introducti
9、on 4g31 Scope 5g32 References 5g32.1 Normative references . 5g32.2 Informative references 5g33 Abbreviations . 7g34 Scenarios 7g35 Current landscape . 9g35.1 Federated Identity Management Frameworks 9g35.2 User-Centric Identity Management Frameworks . 10g35.3 Discovery Frameworks . 12g35.3.1 DNS, DD
10、NS, DNSSEC . 12g35.3.2 HANDLE . 12g35.3.3 IF-MAP 13g35.3.4 Plutarch 13g36 Use Cases . 13g36.1 UC1: Users identity data are scattered across unassociated administrative domains 13g36.1.1 Description 13g36.1.2 Actors 14g36.1.2.1 Actors specific Issues 14g36.1.2.2 Identified gaps . 15g36.1.2.3 Alternat
11、ive Solutions based on existing literature . 15g36.2 UC2: Unknown user authentication . 16g36.2.1 Description 16g36.2.2 Actors 16g36.2.2.1 Actors specific Issues 16g36.2.2.2 Identified gaps . 16g36.3 UC3: Contacting an offline user . 17g36.3.1 Description 17g36.3.2 Actors 17g36.3.2.1 Actors specific
12、 Issues 17g36.3.2.2 Identified gaps . 17g36.3.2.3 Alternative Solutions based on existing literature . 17g37 Conclusion 18g3Annex A (informative): Authors Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest up
13、dates are available on the ETSI Web server (http:/ipr.etsi.org). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web serv
14、er) which are, or may be, or may become, essential to the present document. Foreword This Group Specification (GS) has been produced by ETSI Industry Specification (ISG) Identity and access management for Networks and Services (INS). Introduction Today, discovery of identity data across domains is g
15、enerally realized with two different ways. Discovery Service (DS): A service defined by a group of network entities (providers) which participate in a federation. Identity data (actual data or mappings) are registered in the service and can be provided to all the participants of the group. The locat
16、ion of the discovery service and the protocol for exchanging messages is static and known to the participants of the group (federated model). The “userlocation“ format: By using an identifier of this format, a user directly points to a network point that holds identity information about him (user-ce
17、ntric model). This location may hold information for only one profile of the user (id = email) or for many profiles (id = Virtual Identity i.1). However both of the above ways provide limited discovery of users identity information. For the federated model, only the identity data which exist within
18、the federation of providers can be discovered (and-or associated). Information outside the federation cannot be discovered. Providers that participate in the federation, have previous knowledge of the location of the DS (where to ask for information), and how to exchanged data with it (how to ask fo
19、r information). Efforts to locate data outside predefined federations are usually hampered by the proprietary design of the discovery services and the customized identity formats and protocols that each federation uses. For the User-centric model the use of a specific predefined format instantly exc
20、ludes the discovery of identity data from providers that are not familiar with it. Even though the adoption of a globally accepted identifier would solve major identity issues, this seems to be inapplicable mainly for business reasons and severe protocol modifications in various networks and technol
21、ogies. This work item assumes that all data and attributes required to provide a service are not available within a single service provider. For example proof of residence is required to access online streaming services. An acceptable issuer of this attribute may not be known to the streaming servic
22、es provider beforehand and must be discovered. The purpose of the present document is to investigate the current landscape on the IdM area and evaluate if there is a need for such a discovery mechanism, or whether this can be covered by existing solutions. ETSI ETSI GS INS 006 V1.1.1 (2011-11) 51 Sc
23、ope The present document will focus on gap analysis for global distributed discovery mechanism of identifiers, providers and capabilities. 2 References References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references,
24、 only the cited version applies. For non-specific references, the latest version of the reference document (including any amendments) applies. Referenced documents which are not found to be publicly available in the expected location might be found at http:/docbox.etsi.org/Reference. NOTE: While any
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSIGSINS0062011IDENTITYANDACCESSMANAGEMENTFORNETWORKSANDSERVICESSTUDYTOIDENTIFYTHENEEDFORAGLOBALDISTRIBUTEDDISCOVERYMECHANISM

链接地址:http://www.mydoc123.com/p-733263.html