Authors:
Laurent Gomez
1
and
Ivonne Thomas
2
Affiliations:
1
SAP Research, SAP Labs France, France
;
2
Hasso-Plattner-Institute, University of Potsdam, Germany
Keyword(s):
Access Control, Authentication, Subjective Logic.
Related
Ontology
Subjects/Areas/Topics:
Access Control
;
Data Engineering
;
Databases and Data Security
;
Information and Systems Security
;
Internet Technology
;
Models
;
Paradigm Trends
;
Software Engineering
;
Web Information Systems and Technologies
Abstract:
In order to gain access to a resource protected by an authorization service, a user can be required to authenticate. Traditionally, user authentication is performed by means of a combination of authentication factors, statically specified in the access control policy of the authorization service. In this paper, we propose to improve the flexibility of user authentication by enabling to authenticate using authentication factors at his disposal. Authentication factor are any piece of information used to assess the identity of a user. Capitalizing on opinion metric from subjective logic (Josang, 2001), the authorization service specifies an authentication level to be reached in order to gain access to a resource.