Article (Périodiques scientifiques)
A systematic review of identity and access management requirements in enterprises and potential contributions of self-sovereign identity
Glöckler, Jana; SEDLMEIR, Johannes; FRANK, Muriel-Larissa et al.
2023In Business and Information Systems Engineering
Peer reviewed vérifié par ORBi
 

Documents


Texte intégral
s12599-023-00830-x.pdf
Postprint Éditeur (1.08 MB)
Télécharger
Annexes
12599_2023_830_MOESM1_ESM.pdf
(2.75 MB)
Supplementary file
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Authentication; Digital wallet; IAM; Security; SSI; Verifiable credential
Résumé :
[en] Digital identity and access management (IAM) poses significant challenges for companies. Cyberattacks and resulting data breaches frequently have their root cause in enterprises' IAM systems. During the COVID-19 pandemic, issues with the remote authentication of employees working from home highlighted the need for better IAM solutions. Using a design science research approach, the paper reviews the requirements for IAM systems from an enterprise perspective and identifies the potential benefits of self-sovereign identity (SSI) – an emerging, passwordless paradigm in identity management that provides end users with cryptographic attestations stored in digital wallet apps. To do so, this paper first conducts a systematic literature review followed by an interview study and categorizes IAM system requirements according to security and compliance, operability, technology, and user aspects. In a second step, it presents an SSI-based prototype for IAM, whose suitability for addressing IAM challenges was assessed by twelve domain experts. The results suggest that the SSI-based authentication of employees can address requirements in each of the four IAM requirement categories. SSI can specifically improve manageability and usability aspects and help implement acknowledged best practices such as the principle of least privilege. Nonetheless, the findings also reveal that SSI is not a silver bullet for all of the challenges that today’s complex IAM systems face.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > FINATRAX - Digital Financial Services and Cross-organizational Digital Transformations
NCER-FT - FinTech National Centre of Excellence in Research
Disciplines :
Gestion des systèmes d’information
Sciences informatiques
Auteur, co-auteur :
Glöckler, Jana
SEDLMEIR, Johannes  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > FINATRAX
FRANK, Muriel-Larissa  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > FINATRAX
FRIDGEN, Gilbert  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > FINATRAX
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
A systematic review of identity and access management requirements in enterprises and potential contributions of self-sovereign identity
Date de publication/diffusion :
12 septembre 2023
Titre du périodique :
Business and Information Systems Engineering
ISSN :
2363-7005
eISSN :
1867-0202
Maison d'édition :
Springer, Wiesbaden, Allemagne
Peer reviewed :
Peer reviewed vérifié par ORBi
Focus Area :
Security, Reliability and Trust
Projet FnR :
FNR16326754 - Privacy-preserving Tokenisation Of Artworks, 2021 (01/06/2022-31/05/2025) - Gilbert Fridgen
FNR13342933 - Paypal-fnr Pearl Chair In Digital Financial Services, 2019 (01/01/2020-31/12/2024) - Gilbert Fridgen
Intitulé du projet de recherche :
Fraunhofer Blockchain Center (20-3066-2-6-14)
Organisme subsidiant :
Bavarian Ministry of Economic Affairs, Regional Development and Energy
Disponible sur ORBilu :
depuis le 17 septembre 2023

Statistiques


Nombre de vues
398 (dont 34 Unilu)
Nombre de téléchargements
506 (dont 13 Unilu)

citations Scopus®
 
25
citations Scopus®
sans auto-citations
21
citations OpenAlex
 
32

Bibliographie


Publications similaires



Contacter ORBilu