{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T09:06:42Z","timestamp":1758704802136,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":31,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T00:00:00Z","timestamp":1693267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"MUR National Recovery and Resilience Plan funded by the European Union - NextGenerationEU","award":["PE00000014"],"award-info":[{"award-number":["PE00000014"]}]},{"name":"Futuro & Conoscenza S.r.l"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,29]]},"DOI":"10.1145\/3600160.3600183","type":"proceedings-article","created":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T22:54:41Z","timestamp":1691621681000},"page":"1-11","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Cross-Domain Sharing of User Claims: A Design Proposal for OpenID Connect Attribute Authorities"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6290-3588","authenticated-orcid":false,"given":"Amir","family":"Sharif","sequence":"first","affiliation":[{"name":"Center for Cybersecurity, Fondazione Bruno Kessler, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0308-0080","authenticated-orcid":false,"given":"Francesco Antonio","family":"Marino","sequence":"additional","affiliation":[{"name":"Italian Government Printing Office and Mint, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7567-4526","authenticated-orcid":false,"given":"Giada","family":"Sciarretta","sequence":"additional","affiliation":[{"name":"Center for Cybersecurity, Fondazione Bruno Kessler, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3108-592X","authenticated-orcid":false,"given":"Giuseppe","family":"De Marco","sequence":"additional","affiliation":[{"name":"Department for digital transformation, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2853-4269","authenticated-orcid":false,"given":"Roberto","family":"Carbone","sequence":"additional","affiliation":[{"name":"Center for Cybersecurity, Fondazione Bruno Kessler, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7269-9285","authenticated-orcid":false,"given":"Silvio","family":"Ranise","sequence":"additional","affiliation":[{"name":"Center for Cybersecurity, Fondazione Bruno Kessler, Italy and University of Trento, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"AGID. 2021. Linee Guida Attribute Authority SPID. https:\/\/www.agid.gov.it\/sites\/default\/files\/repository_files\/llgg_attribute_authorities_0.pdf."},{"key":"e_1_3_2_1_2_1","unstructured":"AGID. 2022. Linee Guida Attribute Authority. https:\/\/www.agid.gov.it\/sites\/default\/files\/repository_files\/llgg_attribute_authority-allegato_tecnico_oas3.pdf."},{"key":"e_1_3_2_1_3_1","unstructured":"AGID. 2023. SPID CIE OpenID Connect Technical Specifications. https:\/\/docs.italia.it\/italia\/spid\/spid-cie-oidc-docs\/it\/versione-corrente\/index.html."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.3390\/info10060210"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3115853"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9068"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC9068"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102486.1102489"},{"key":"e_1_3_2_1_9_1","volume-title":"Internet Engineering Task Force (IETF)","author":"Bradley John","year":"2020","unstructured":"John Bradley, Brian Campbell, Torsten Lodderstedt, and Nat Sakimura. 2020. OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens (RFC8705). Internet Engineering Task Force (IETF) (2020)."},{"key":"e_1_3_2_1_10_1","first-page":"2015","article-title":"SAML Version 2.0 Errata 05","volume":"18","author":"Cantor S","year":"2012","unstructured":"S Cantor. 2012. SAML Version 2.0 Errata 05. Retrieved March 18 (2012), 2015.","journal-title":"Retrieved March"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2523514.2526998"},{"key":"e_1_3_2_1_12_1","volume-title":"Internet Engineering Task Force (IETF)","author":"Fett Daniel","year":"2023","unstructured":"Daniel Fett, Brian Campbell, John Bradley, Torsten Lodderstedt, Mike Jones, and David Waite. 2023. OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) (draft-ietf-DPoP-14). Internet Engineering Task Force (IETF) (2023)."},{"key":"e_1_3_2_1_13_1","volume-title":"The OAuth 2.0 Authorization Framework (RFC6749). Internet Engineering Task Force (IETF)","author":"Hardt Dick","year":"2012","unstructured":"Dick Hardt. 2012. The OAuth 2.0 Authorization Framework (RFC6749). Internet Engineering Task Force (IETF) (2012)."},{"key":"e_1_3_2_1_14_1","volume-title":"OpenID Connect Federation 1.0 - Draft 27","author":"Hedberg Roland","year":"2023","unstructured":"Roland Hedberg, Mike Jones, Andreas\u00a0\u00c5kre Solberg, John Bradley, and Giuseppe De\u00a0Marco. 2023. OpenID Connect Federation 1.0 - Draft 27. The OpenID Foundation, specification (2023)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Michael Jones. 2015. JSON Web Key (JWK) (RFC7517). (2015).","DOI":"10.17487\/RFC7517"},{"key":"e_1_3_2_1_16_1","volume-title":"OpenID Connect Front-Channel Logout 1.0","author":"Jones Mike","year":"2022","unstructured":"Mike Jones. 2022. OpenID Connect Front-Channel Logout 1.0. The OpenID Foundation, specification (2022)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7519"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC7516"},{"key":"e_1_3_2_1_19_1","volume-title":"Internet Engineering Task Force (IETF)","author":"Jones Mike","year":"2020","unstructured":"Mike Jones, Anthony Nadalin, Brian Campbell, John Bradley, and Chuck Mortimore. 2020. OAuth 2.0 Token Exchange (RFC8693). Internet Engineering Task Force (IETF) (2020)."},{"key":"e_1_3_2_1_20_1","volume-title":"Internet Engineering Task Force (IETF)","author":"Lodderstedt T","year":"2023","unstructured":"T Lodderstedt, J Bradley, A Labunets, and D Fett. 2023. OAuth 2.0 Security Best Current Practice (draft-ietf-oauth-security-topics-22). Internet Engineering Task Force (IETF) (2023)."},{"key":"e_1_3_2_1_21_1","volume-title":"Internet Engineering Task Force (IETF)","author":"Lodderstedt Torsten","year":"2013","unstructured":"Torsten Lodderstedt, Mark McGloin, and Phil Hunt. 2013. OAuth 2.0 Threat Model and Security Considerations (RFC6819). Internet Engineering Task Force (IETF) (2013)."},{"key":"e_1_3_2_1_22_1","volume-title":"Internet Engineering Task Force (IETF)","author":"Lodderstedt Torsten","year":"2023","unstructured":"Torsten Lodderstedt, Justin Richer, and Brian Campbell. 2023. OAuth 2.0 Reach Authorization Request (RAR) (draft-ietf-RAR-23). Internet Engineering Task Force (IETF) (2023)."},{"key":"e_1_3_2_1_23_1","unstructured":"OWASP. 2019. OWASP API Security Project. https:\/\/owasp.org\/www-project-api-security\/."},{"key":"e_1_3_2_1_24_1","volume-title":"Internet Engineering Task Force (IETF)","author":"Richer Justin","year":"2015","unstructured":"Justin Richer. 2015. OAuth 2.0 token introspection (RFC7662). Internet Engineering Task Force (IETF) (2015)."},{"key":"e_1_3_2_1_25_1","volume-title":"OpenID Connect Core 1.0 incorporating errata set 1","author":"Sakimura Nat","year":"2014","unstructured":"Nat Sakimura, John Bradley, Mike Jones, Breno De\u00a0Medeiros, and Chuck Mortimore. 2014. OpenID Connect Core 1.0 incorporating errata set 1. The OpenID Foundation, specification 335 (2014)."},{"key":"e_1_3_2_1_26_1","series-title":"Draft 02","volume-title":"OpenID Connect Claims Aggregation","author":"Sakimura Nat","year":"2022","unstructured":"Nat Sakimura, Edmond Jay, and Tobias Looker. 2022. OpenID Connect Claims Aggregation (Draft 02). The OpenID Foundation, draft (2022)."},{"key":"e_1_3_2_1_27_1","unstructured":"Martin Schanzenbach Christian Grothoff Hansj\u00fcrg Wenger and Maximilian Kaul. 2021. Decentralized Identities for Self-sovereign End-users (DISSENS). (2021)."},{"key":"e_1_3_2_1_28_1","volume-title":"ZKlaims: Privacy-preserving Attribute-based Credentials using Non-interactive Zero-knowledge Techniques. arXiv preprint arXiv:1907.09579","author":"Schanzenbach Martin","year":"2019","unstructured":"Martin Schanzenbach, Thomas Kilian, Julian Sch\u00fctte, and Christian Banse. 2019. ZKlaims: Privacy-preserving Attribute-based Credentials using Non-interactive Zero-knowledge Techniques. arXiv preprint arXiv:1907.09579 (2019)."},{"key":"e_1_3_2_1_29_1","volume-title":"The eIDAS Regulation: A Survey of Technological Trends for European Electronic Identity Schemes. Applied Sciences","author":"Sharif Amir","year":"2022","unstructured":"Amir Sharif, Matteo Ranzi, Roberto Carbone, Giada Sciarretta, Francesco\u00a0Antonio Marino, and Silvio Ranise. 2022. The eIDAS Regulation: A Survey of Technological Trends for European Electronic Identity Schemes. Applied Sciences (2022)."},{"key":"e_1_3_2_1_30_1","volume-title":"JSON Web Token (JWT) Embedded Tokens (draft-07). Internet Engineering Task Force (IETF)","author":"Shekh-Yusef Rifaat","year":"2022","unstructured":"Rifaat Shekh-Yusef, Hardt Dick, and Giuseppe De\u00a0Marco. 2022. JSON Web Token (JWT) Embedded Tokens (draft-07). Internet Engineering Task Force (IETF) (2022)."},{"key":"e_1_3_2_1_31_1","unstructured":"SWAGGER. 2018. Open API Specification. https:\/\/swagger.io\/specification\/."}],"event":{"name":"ARES 2023: The 18th International Conference on Availability, Reliability and Security","acronym":"ARES 2023","location":"Benevento Italy"},"container-title":["Proceedings of the 18th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3600183","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3600160.3600183","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:13Z","timestamp":1750178173000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3600183"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,29]]},"references-count":31,"alternative-id":["10.1145\/3600160.3600183","10.1145\/3600160"],"URL":"https:\/\/doi.org\/10.1145\/3600160.3600183","relation":{},"subject":[],"published":{"date-parts":[[2023,8,29]]},"assertion":[{"value":"2023-08-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}