{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/49748"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/49748","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Federated identity management systems for cyberinfrastructure: SAML vs. PKIX","abstract":"In scientific infrastructures researchers accessing computing and other resources (e.g., instruments, data) across institutional boundaries rely on federated identity management systems. Multiple competing technologies are in use for this purpose, including Security Assertion Markup Language (SAML) and Public Key Infrastructure with X.509 Certificates (PKIX). These systems have found favor in different scientific computing communities but it is unclear what the difference in preference is based upon. In this study we discuss the security, usability, privacy and trust model assumptions of SAML and PKIX systems for researchers authenticating to grid computing systems across multiple domains. We provide a comparison of these systems to highlight where they provide equivalent functionality and where one technology is superior.","abstract_html":"In scientific infrastructures researchers accessing computing and other resources (e.g., instruments, data) across institutional boundaries rely on federated identity management systems. Multiple competing technologies are in use for this purpose, including Security Assertion Markup Language (SAML) and Public Key Infrastructure with X.509 Certificates (PKIX). These systems have found favor in different scientific computing communities but it is unclear what the difference in preference is based upon. In this study we discuss the security, usability, privacy and trust model assumptions of SAML and PKIX systems for researchers authenticating to grid computing systems across multiple domains. We provide a comparison of these systems to highlight where they provide equivalent functionality and where one technology is superior.","abstract_has_math":false,"creators":["Hayes, Thomas"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Bobba, Rakesh","Basney, Jim"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2014,"date_issued":"2014-05-30T17:07:42Z","date_published":"2014-05-30T17:07:42Z","updated_at":"2026-07-22T22:25:40Z","subjects":["federated identity","cyberinfrastructure","grid computing"],"languages":["en"],"rights":["Copyright 2014 Thomas Hayes"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/49748","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Bobba, Rakesh","Basney, Jim"]},{"key":"dc:creator","label":"Author","values":["Hayes, Thomas"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2014-05-30T17:07:42Z","2016-09-22T20:59:05Z","2014-05"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["federated identity","cyberinfrastructure","grid computing"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2014 Thomas Hayes"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/49748"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["In scientific infrastructures researchers accessing computing and other resources (e.g., instruments, data) across institutional boundaries rely on federated identity management systems. Multiple competing technologies are in use for this purpose, including Security Assertion Markup Language (SAML) and Public Key Infrastructure with X.509 Certificates (PKIX). These systems have found favor in different scientific computing communities but it is unclear what the difference in preference is based upon. In this study we discuss the security, usability, privacy and trust model assumptions of SAML and PKIX systems for researchers authenticating to grid computing systems across multiple domains. We provide a comparison of these systems to highlight where they provide equivalent functionality and where one technology is superior.","Item withdrawn by Laura Spradlin (lspradl2@illinois.edu) on 2014-04-28T13:29:51Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Hayes_Thomas.pdf: 229142 bytes, checksum: 852ddb0640f9da2d1f574290e7e5c122 (MD5)","Made available in DSpace on 2014-05-30T17:07:42Z (GMT). No. of bitstreams: 2 Thomas_Hayes.pdf: 229142 bytes, checksum: 852ddb0640f9da2d1f574290e7e5c122 (MD5) license.txt: 4060 bytes, checksum: 966ea4353aa9525605121132b709243d (MD5)","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (robbins.sd@gmail.com) on 2014-05-30T17:09:59Z Item is restricted until 2016-05-30T17:09:03Z","Restriction data tranferred 2014-07-01T11:39:29-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2016-05-30 12:09:03 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 49799 on 2016-09-22T20:59:05Z."]},{"key":"dc:title","label":"Title","values":["Federated identity management systems for cyberinfrastructure: SAML vs. PKIX"]}]}],"canonical_facts":{"dc:contributor":["Bobba, Rakesh","Basney, Jim"],"dc:creator":["Hayes, Thomas"],"dc:date":["2014-05-30T17:07:42Z","2016-09-22T20:59:05Z","2014-05"],"dc:description":["In scientific infrastructures researchers accessing computing and other resources (e.g., instruments, data) across institutional boundaries rely on federated identity management systems. Multiple competing technologies are in use for this purpose, including Security Assertion Markup Language (SAML) and Public Key Infrastructure with X.509 Certificates (PKIX). These systems have found favor in different scientific computing communities but it is unclear what the difference in preference is based upon. In this study we discuss the security, usability, privacy and trust model assumptions of SAML and PKIX systems for researchers authenticating to grid computing systems across multiple domains. We provide a comparison of these systems to highlight where they provide equivalent functionality and where one technology is superior.","Item withdrawn by Laura Spradlin (lspradl2@illinois.edu) on 2014-04-28T13:29:51Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Hayes_Thomas.pdf: 229142 bytes, checksum: 852ddb0640f9da2d1f574290e7e5c122 (MD5)","Made available in DSpace on 2014-05-30T17:07:42Z (GMT). No. of bitstreams: 2 Thomas_Hayes.pdf: 229142 bytes, checksum: 852ddb0640f9da2d1f574290e7e5c122 (MD5) license.txt: 4060 bytes, checksum: 966ea4353aa9525605121132b709243d (MD5)","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (robbins.sd@gmail.com) on 2014-05-30T17:09:59Z Item is restricted until 2016-05-30T17:09:03Z","Restriction data tranferred 2014-07-01T11:39:29-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2016-05-30 12:09:03 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 49799 on 2016-09-22T20:59:05Z."],"dc:identifier":["http://hdl.handle.net/2142/49748"],"dc:language":["en"],"dc:rights":["Copyright 2014 Thomas Hayes"],"dc:subject":["federated identity","cyberinfrastructure","grid computing"],"dc:title":["Federated identity management systems for cyberinfrastructure: SAML vs. PKIX"],"dc:type":["text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:40Z"}