Centro de Documentação da PJ | ||||
| KENT, Stephen T., e outro Who goes there? [Documento electrónico] : authentication through the lens of privacy / ed. Stephen T. Kent, ed. Lynette I. Millett ; Committee on Authentication Technologies and Their Privacy Implications. National Academy of Sciences.- Washington, DC : National Academies Press, 2003.- 1 CD-ROM ; 12 cm Ficheiro de 3,93 MB em formato PDF (232 p.). ISBN 0-309-52654-X SISTEMA DE SEGURANÇA, PROTECÇÃO E SEGURANÇA DE DADOS, TECNOLOGIA, BIOMETRIA Executive summary. 1 Introduction and overview. Definitions and terminology. Authentication in daily life. Current tensions. Four overarching privacy concerns. What this report does and does not do. 2 Authentication in the abstract. What is authentication and why is it done? Three parties to authentication. Authenticating to authorize. Authenticating to hold accountable. What do we authenticate? Identifiers. Attributes. Statements. How do we authenticate? Authenticating physical identity. Authenticating psychological identity. Authenticating possession of an artifact. The relationship between authentication and identification. 3 privacy challenges in authentication systems. Privacy impact of the decision to authenticate. Access control and information systems. The legal foundations of privacy. Constitutional roots of privacy. The common law roots of privacy law. Statutory privacy protections. Information privacy and fair information practices. Privacy of communications. Concluding remarks. 4 Security and usability. Threat models. Threats. Dealing with threats. Authentication and people—user-centered design. Lessons from user-centered design. Lessons from cognitive and social psychology. Factors behind the technology choice. Systems and secondary use. Concluding remarks. 5 Authentication technologies. Technological flavors of authentication. Basic types of authentication mechanisms. Something you know. Something you have. Something you are. Multifactor authentication. Centralized versus decentralized authentication systems. Security considerations for individual authentication technologies. Cost considerations for individual authentication technologies. Concluding remarks. 6 Authentication, privacy, and the roles of government. Regulator of private sector and public agency behaviors and processes. Government-wide law and policy. Agency- or program-specific law and policies. Regulation of private sector information management activity. Policy activity in the early 2000s. Summary. Government as issuer of identity documents. The tangled web of government-issued identity documents. Threats to foundational documents. Government as relying party for authentication services. Access certificates for electronic services. The internal revenue service—electronic tax filing. The social security administration and pebes. Nationwide identity systems. Concluding remarks. 7 A toolkit for privacy in the context of authentication. Privacy-impact toolkit. Attribute choice. Identifier selection. Identity selection. The authentication phase. Concluding remarks. Appendixes. A Biographies of committee members and staff. B Briefers to the study committee. C Some key concepts. What is CSTB? |