|
|
March
2008
Guest Editors' Introduction I'm Pc01002/SpringPeeper/ED288l.6; Who are You? Susan Landau and Deirdre K. Mulligan In considering identity management, the first issue is—What is identity? This is, of course, an issue that has plagued poets, philosophers, and playwrights for centuries. We’re concerned with a more prosaic version of the question: How does an entity recognize another entity? This important question occurs when access to resources, such as health or financial records, services, or benefits, is limited to specific entities. The entity in question could be a person, a computer, or even a device with quite limited memory and computational power. In this issue of IEEE Security & Privacy—the first of what we suspect will be several special issues on identity management—we have chosen to focus on identity management in which the entity being identified is a person. January 2008 S&P: 2007 Reviewers Thank You to Our 2007 Reviewers! IEEE Security & Privacy expresses our gratitude to our reviewers during 2007. |
|
March
2008
Building Security In Dynamic Security Assertion Markup Language: Simplifying Single Sign-On Patrick Harding, Leif Johansson, and Nate Klingenstein Dynamic Security Assertion Markup Language (SAML) simplifies the establishment of secure single sign-on between Web applications in different organizations by automating the exchange of SAML configuration information and simplifying cryptographic trust establishment. March 2008 From the Editors Lessons from Electrification for Identification Marc Donner As we've seen with the electrical system's evolution and the reengineering of the US voting system, change makes us rediscover essential assumptions and expectations about systems as well as their complexity and inherent risks. In the case of e-voting, the debate reeducated society at large about our expectations of the process, why we have such things as secret ballots, and what it takes to provide confidence that the process has been conducted fairly. With this issue of S&P, we hope that you'll be better prepared to participate in the debate over identity management and ensure that the nontechnical policy makers who will make many of the key decisions can make high-quality choices. |
Table of Contents RSS: Subscribe to our
Table of Contents RSS feed and be among the first to find out what's new in
each issue. For more information on how to use this feed, click
here.





