Understanding Windows CardSpace: An Introduction to the Concepts and Challenges of Digital Identities
暫譯: 理解 Windows CardSpace:數位身份的概念與挑戰入門

Vittorio Bertocci, Garrett Serack, Caleb Baker

  • 出版商: Addison Wesley
  • 出版日期: 2008-01-06
  • 售價: $2,040
  • 貴賓價: 9.5$1,938
  • 語言: 英文
  • 頁數: 384
  • 裝訂: Paperback
  • ISBN: 0321496841
  • ISBN-13: 9780321496843
  • 相關分類: 數位訊號處理 Dsp
  • 已絕版

相關主題

商品描述

Windows CardSpace empowers organizations to prevent identity theft and systematically address a broad spectrum of security and privacy challenges. Understanding Windows CardSpaceis the first insider’s guide to Windows CardSpace and the broader topic of identity management for technical and business professionals. Drawing on the authors’ unparalleled experience earned by working with the CardSpace product team and by implementing state-of-the-art CardSpace-based systems at leading enterprises, it offers unprecedented insight into the realities of identity management: from planning and design through deployment.

Part I introduces the fundamental concepts of user-centered identity management, explains the context in which Windows CardSpace operates, and reviews the problems CardSpace aims to solve. Next, the authors walk through CardSpace from a technical standpoint, describing its technologies, elements, artifacts, operations and development practices, and usage scenarios. Finally, they carefully review the design and business considerations associated with architecting solutions based on CardSpace or any other user-centered identity management

system. Coverage includes

  • The limitations of current approaches to authentication and identity management
  • Detailed information on advanced Web services
  • The Identity Metasystem, the laws of identity, and the ideal authentication system
  • Windows CardSpace: What it is, how it works, and how developers and managers can use it in their organizations
  • CardSpace technology: user experience, Information Cards, private desktops, and integration with .NET 3.5 and Windows Vista
  • CardSpace implementation: from HTML integration through federation, Web services integration, and beyond
  • Adding personal card support to a website: a detailed, scenario-based explanation
  • Choosing or becoming an identity provider: opportunities, business impacts, operational issues, and pitfalls to avoid
  • Using CardSpace to leverage trust relationships and overcome phishing

Whether you’re a developer, security specialist, or business decision-maker, this book will answer your most crucial questions about identity management, so you can protect everything that matters: your people, your assets, your partners, and your customers.

 

Foreword xv

Preface xviii

Part I Setting the Context

Chapter 1: The Problem 3

  The Advent of Profitable Digital Crime 4

  Passwords: Ascent and Decline 29

  The Babel of Cryptography 36

  The Babel of Web User Interfaces 79

  Summary 84

Chapter 2: Hints Toward a Solution 87

  A World Without a Center 89

  The Seven Laws of Identity 92

  The Identity Metasystem 110

  Trust 115

  WS-* Web Services Specifications: The Reification of the Identity Metasystem 136

  Presenting Windows CardSpace 161

  Summary 164

Part II THE TECHNOLOGY

Chapter 3: Windows CardSpace 169

  CardSpace Walkthroughs 169

  Is CardSpace Just for Websites? 175

  System Requirements 176

  What CardSpace Provides 177

  A Deeper Look at Information Cards 184

  Features of the CardSpace UI 204

  Common CardSpace Management Tasks 210

  User Experience Changes in .NET Framework 3.5 218

  Summary 221

Chapter 4: CardSpace Implementation 223

  Using CardSpace in the Browser 224

  Federation with CardSpace 248

  CardSpace and Windows Communication Foundation 252

  CardSpace Without Web Services 262

  Summary 268

Chapter 5: Guidance for a Relying Party 269

  Deciding to Be a Relying Party 270

  Putting CardSpace to Work 274

  Privacy and Liability 299

  Summary 302

Part III PRACTICAL CONSIDERATIONS

Chapter 6: Identity Consumers 305

  Common Misconceptions about Becoming an Identity Provider 306

  Criteria for Selecting an Identity Provider 309

  Relying on an IP 315

  Migration Issues 320

  Summary 321

Chapter 7: Identity Providers 323

  Uncovering the Rationale for Becoming an Identity Provider 324

  What Does an Identity Provider Have to Offer? 334

  Walking a Mile in the User’s Shoes 338

  An Organization’s Identity 341

  Summary 342

Index 343

商品描述(中文翻譯)

Windows CardSpace 使組織能夠防止身份盜竊,並系統性地解決廣泛的安全和隱私挑戰。《Understanding Windows CardSpace》是針對 Windows CardSpace 及更廣泛的身份管理主題的第一本內部指南,專為技術和商業專業人士而設。該書借助作者在 CardSpace 產品團隊工作的無與倫比的經驗,以及在領先企業實施最先進的基於 CardSpace 的系統,提供了對身份管理現實的前所未有的洞察:從規劃和設計到部署。

第一部分介紹了以用戶為中心的身份管理的基本概念,解釋了 Windows CardSpace 運作的背景,並回顧了 CardSpace 旨在解決的問題。接下來,作者從技術角度逐步介紹 CardSpace,描述其技術、元素、工件、操作和開發實踐,以及使用場景。最後,他們仔細回顧了與基於 CardSpace 或任何其他以用戶為中心的身份管理系統架構解決方案相關的設計和商業考量。

涵蓋內容包括:

- 當前身份驗證和身份管理方法的局限性
- 先進 Web 服務的詳細信息
- 身份元系統、身份法則和理想的身份驗證系統
- Windows CardSpace:它是什麼、如何運作,以及開發人員和管理者如何在其組織中使用它
- CardSpace 技術:用戶體驗、信息卡、私人桌面,以及與 .NET 3.5 和 Windows Vista 的整合
- CardSpace 實施:從 HTML 整合到聯邦、Web 服務整合及其他
- 為網站添加個人卡支持:詳細的基於場景的解釋
- 選擇或成為身份提供者:機會、商業影響、操作問題和應避免的陷阱
- 使用 CardSpace 利用信任關係並克服網絡釣魚

無論您是開發人員、安全專家還是商業決策者,本書將回答您關於身份管理的最關鍵問題,讓您能夠保護一切重要的事物:您的員工、資產、合作夥伴和客戶。

前言 xv
序言 xviii
第一部分 設定背景
第 1 章:問題 3
利潤豐厚的數位犯罪的出現 4
密碼:興起與衰退 29
密碼學的巴別塔 36
網頁用戶介面的巴別塔 79
總結 84
第 2 章:解決方案的提示 87
無中心的世界 89
七條身份法則 92
身份元系統 110
信任 115
WS-* Web 服務規範:身份元系統的具象化 136
介紹 Windows CardSpace 161
總結 164
第二部分 技術
第 3 章:Windows CardSpace 169
CardSpace 演練 169
CardSpace 僅適用於網站嗎? 175
系統需求 176
CardSpace 提供的功能 177
深入了解信息卡 184
CardSpace UI 的特性 204
常見的 CardSpace 管理任務 210
.NET Framework 3.5 中的用戶體驗變化 218
總結 221
第 4 章:CardSpace 實施 223
在瀏覽器中使用 CardSpace 224
與 CardSpace 的聯邦 248
CardSpace 和 Windows 通信基礎架構 252
無 Web 服務的 CardSpace 262
總結 268
第 5 章:依賴方的指導 269
決定成為依賴方 270
實現 CardSpace 的工作 274
隱私和責任 299
總結 302
第三部分 實用考量
第 6 章:身份消費者 305
成為身份提供者的常見誤解 306
選擇身份提供者的標準 309
依賴身份提供者 315
遷移問題 320
總結 321
第 7 章:身份提供者 323
揭示成為身份提供者的理由 324
身份提供者能提供什麼? 334
站在用戶的立場思考 338
組織的身份 341
總結 342
索引 343