Identity and access management (I&AM) is the umbrella term for managing users and their permissions. It is required for users to access different services. These services can either be provided from their home organization, like a company or university, or from external service providers, e.g., cooperation partners. I&AM provides the management of identifiers with the attributes, credentials, roles, and permissions the user has. Today, the requirements have evolved from simply accessing individual web services in the internet or at a company to the majority of all IT services from different service providers with various accounts. Several identity management models have been created with different approaches within. In order to adjust to heterogeneous environments, use cases, and the evolution of identity management, this paper extends known requirements for identity management. Existing models and approaches for identity management are mapped to the derived requirements. Based on the mapping, advantages, disadvantages, and gaps are identified. Current approaches suffer, as an example, from trustworthiness and liability issues. Interoperability issues are even more inherent as the approaches partly develop apart, forming an heterogeneous environment. The results from this analysis emphasize the need for one holistic identity management framework.
翻译:身份和访问管理(I&AM)是管理用户及其许可的总括术语,用户需要获得不同的服务,这些服务可以来自其母国组织,如公司或大学,也可以来自外部服务供应商,例如合作伙伴。 I&AM提供身份标识管理,提供用户拥有的属性、证书、作用和许可。今天,要求已经从仅仅在互联网上或公司上获取个人网络服务发展到拥有不同账户的不同服务供应商的大多数信息技术服务。若干身份管理模式是内部采用不同方法创建的。为了适应不同环境、使用案例和身份管理的发展,本文件扩展了已知的身份管理要求。现有身份管理模式和办法与衍生要求相匹配。根据绘图、优势、劣势和差距,找出了现有方法,例如,信任度和赔偿责任问题。互可操作性问题随着方法的局部发展,形成一个不同的环境,因此更为内在。这一分析的结果强调需要一个整体身份管理框架。