<?xml version="1.0" encoding="UTF-8"?><rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel rdf:about="http://dl.gi.de/handle/20.500.12116/20999">
<title>P277 - Open Identity Summit 2017</title>
<link>http://dl.gi.de/handle/20.500.12116/20999</link>
<description/>
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/3585"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/3581"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/3579"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/3580"/>
</rdf:Seq>
</items>
<dc:date>2026-07-23T05:22:58Z</dc:date>
</channel>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/3585">
<title>Derived Partial Identities Generated from App Permissions</title>
<link>http://dl.gi.de/handle/20.500.12116/3585</link>
<description>Derived Partial Identities Generated from App Permissions
Fritsch, Lothar; Momen, Nurul
Fritsch, Lothar; Roßnagel, Heiko; Hühnlein, Detlef
This article presents a model of partial identities derived from app permissions that is based on Pfitzmann and Hansen’s terminology for privacy [PH10]. The article first shows how app permissions accommodate the accumulation of identity attributes for partial digital identities by building a model for identity attribute retrieval through permissions. Then, it presents an experimental survey of partial identity access for selected app groups. By applying the identity attribute retrieval model on the permission access log from the experiment, we show how apps’ permission usage is providing to identity profiling.
</description>
<dc:date>2017-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/3581">
<title>Towards secure and standard-compliant implementations of the PSD2 Directive</title>
<link>http://dl.gi.de/handle/20.500.12116/3581</link>
<description>Towards secure and standard-compliant implementations of the PSD2 Directive
Wich, Tobias; Nemmert, Daniel; Hühnlein, Detlef
Fritsch, Lothar; Roßnagel, Heiko; Hühnlein, Detlef
The present article provides a compact overview of the most important requirements of the so-called “Payment Services Directive 2” (PSD2) [Di15], together with the related Regulatory Technical Standard on authentication and communication [Eu17] according to Article 98, and outlines how the pivotal “Access-to-Account-Interface” can be securely implemented based on widely acknowledged international standards.
</description>
<dc:date>2017-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/3579">
<title>Password Assistance</title>
<link>http://dl.gi.de/handle/20.500.12116/3579</link>
<description>Password Assistance
Horsch, Moritz; Braun, Johannes; Buchmann, Johannes
Fritsch, Lothar; Roßnagel, Heiko; Hühnlein, Detlef
For decades, users are not able to realize secure passwords for their user accounts at Internet services. Users’ passwords need to fulfil general security requirements and the password requirements of services. Furthermore, users need to cope with different password implementations at services. Finally, users need to perform a multitude of tasks to properly manage their large password portfolios. This is practically impossible. In this paper, we introduce the vision of a password assistant. It supports users in all duties and tasks with regard to their passwords, from the creation of secure passwords to the recovery of them in case of loss. Moreover, it provides an extensive automatization of all password tasks that reduces the users’ efforts and activities to deal with passwords to a minimum. A password assistant enables high security for passwords as well as improves their ease of use. First, we provide a detailed description of the problem of users to realize secure passwords for their accounts in practice. Second, we outline the vision of a password assistant, describe its technical foundation, and introduce the related open-source project starting to realize the first password assistant.
</description>
<dc:date>2017-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/3580">
<title>An explorative approach on the impact of external and organizational events on information security</title>
<link>http://dl.gi.de/handle/20.500.12116/3580</link>
<description>An explorative approach on the impact of external and organizational events on information security
Ajazaj, Ilirjana; Kurowski, Sebastian
Fritsch, Lothar; Roßnagel, Heiko; Hühnlein, Detlef
This contribution aims at the research question on which observable organizational events occur prior to an information security incident, and how these may relate to the organization. It therefore uses a dataset that was built using Google News, and the list of data breaches from [Mc17] to analyse which organizational events occur most often. It provides a categorization of these events, which were built by using a grounded theory approach. On the other hand, causal chains are constructed by  sing the sociologic system theory and constructivism. Both, the causal chains and the organizational event categories are applied together within this contribution to discuss, the likelihood of the causalities of the occurred events. However, events, such as financial gains also exhibit a higher occurrence prior to an information security incident. This contribution is a speculative, yet first approach on this question. Further research will focus on refining the constructed causalities.
</description>
<dc:date>2017-01-01T00:00:00Z</dc:date>
</item>
</rdf:RDF>
