Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > How do anonymous credentials and selective disclosure certificates affect enterprise IAM?
Ask The Security Expert: Questions & Answers
EMAIL THIS

How do anonymous credentials and selective disclosure certificates affect enterprise IAM?

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 27 July 2007
Lately I've read a lot about anonymous credentials and selective disclosure certificates. What do these terms mean and how do they affect enterprise IAM?

>
The technologies you describe are used as a way to prevent disclosure of too much information about a user during the authentication process. Access management systems create profiles for each user who has been granted access. Additionally, some systems use digital certificates to further verify the user's identity. Depending on the system, these digital certificates may contain a lot of information about an individual user's identity.

Since the entire digital certificate is used during authentication, if compromised it could lead to a breach of sensitive information about the user, some of which could be used later for stealing the legitimate user's identity or authentication credentials for malicious access.

The technology, also called minimal disclosure certificates, was developed in 2000 by Stefan Brands, a cryptographer and professor of computer science at McGill University in Montreal.

Here's a scenario to explain how it works. Someone goes into a bar and the bartender asks for the person's driver's license to verify if he or she is of legal age to drink. Most likely, the bartender just looks at the person's date of birth and isn't interested in the name, address or other personal information. Once the bartender is satisfied, the person puts their license away and is allowed to stay in the bar.

But in open networks -- like the Web and the Internet -- an entire digital certificate may be exposed to the whole world over the wire, where its contents can be sniffed and stolen by hackers interested in stealing authentication credentials.

Minimal disclosure certificates solve that problem by only providing enough information from the user's DC to grant access to a system for a specific request. The user's whole identity or credentials aren't served up to the system requesting authentication.

Anonymous credentials are a similar concept, but are more about hiding credentials altogether rather than selective release of identity information.

Brands has a fascinating blog on the subject, The Identity Corner, where he explains and debates the finer points of these two concepts. He says there are three privacy properties of minimal disclosure: minimal traceability back to the user, minimal linkage back to the user and selective disclosure about the user.

Their effect on enterprise access management systems is hard to say right now, since the technology is still currently evolving and not widely adopted. Minimal disclosure certificates and anonymous credentials require access management systems with a high degree of granularity, meaning such systems must be capable of being tuned to pick and choose which pieces of users' identities can be used for authentication.

The technology is being discussed as part of CardSpace, a Microsoft identity management initiative, and as part of the Security Assertions Markup Language (SAML), a similar open source project.

For more information:

  • Joel Dubin discusses the pros and cons associated with creating a personal digital certificate.
  • In this expert response, application security pro Michael Cobb emphasizes the importance of keeping your Web server certificates up-to-date.


  • BROWSE BY TAG
    Identity Management and Access Control,   PKI and Digital Certificates,   Enterprise Identity and Access Management,   User Authentication Services,   Two-Factor and Multifactor Authentication Strategies,   Expert Archive: Identity Management and Access Control,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Identity Management and Access Control
    Is Identity Management as a Service (IDaaS) a good idea?
    How to log in to multiple servers with federated single sign-on (SSO)
    How to confirm the receipt of an email with security protocols
    Learn about enterprise strategy for server virtualization single sign-on
    Employee information security awareness training for new IAM systems
    Can you combine RFID tag technology with GPS to track stolen goods?
    Is there a free enterprise-caliber password-management tool?
    Cryptosystem attacks that do not involve obtaining the decryption key
    Can any firm or organization get a digital signature certificate?
    Should the CTO have domain administrator access?

    PKI and Digital Certificates
    Best Authentication Products
    DoD urges less network anonymity, more PKI use
    Researchers to demonstrate new EV SSL man-in-the-middle hacks
    Portable security storage device could replace OTP devices
    What is most misunderstood about EV SSL certificates?
    VeriSign addresses MD5 flaw
    Rogue digital certificates strike blow to Internet security
    Can any firm or organization get a digital signature certificate?
    How to obtain a digital certificate for a server
    PKI and digital certificates: Security, authentication and implementation
    PKI and Digital Certificates Research

    Two-Factor and Multifactor Authentication Strategies
    Two-factor authentication, vigilance foil password theft
    Security on a budget: How to make the most of authentication tools
    Best Authentication Products
    Best Identity and Access Management Products
    Are 'strong authentication' methods strong enough for compliance?
    PCI compliance requirement 7: Restrict access
    PCI compliance requirement 9: Physical access
    Best practices: How to implement and maintain enterprise user roles
    Changing times for identity management
    RSA researcher Ari Juels: RFID tags may be easily hacked

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    authentication server  (SearchSecurity.com)
    Certificate Revocation List  (SearchSecurity.com)
    Digital Signature Standard  (SearchSecurity.com)
    HDCP  (SearchSecurity.com)
    MD2  (SearchSecurity.com)
    MD4  (SearchSecurity.com)
    MD5  (SearchSecurity.com)
    nonrepudiation  (SearchSecurity.com)
    PKI  (SearchSecurity.com)
    public key  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts