IDEAS home Printed from https://ideas.repec.org/p/pra/mprapa/7850.html
   My bibliography  Save this paper

A Network-Economic Policy Study of Identity Management Systems and Implications for Security and Privacy Policy

Author

Listed:
  • Repkine, Alexandre
  • Hwang, Junseog

Abstract

Solving the problems associated with identity management in the “virtual” world is proving to be one of the keys to full realization of the economic and social benefits of networked information systems. By definition, the virtual world lacks the rich combination of sensory and contextual cues that permit organizations and individual humans interacting in the physical world to reliably identify people and authorize them to engage in certain transactions or access specific resources. Being able to determine who an online user is and what they are authorized to do thus requires an identity management infrastructure. Some of the most vexing problems associated with the Internet (the deluge of spam, the need to regulate access to certain kinds of content, securing networks from intrusion and disruption, problems of inter-jurisdictional law enforcement related to online activities, impediments to the sharing of distributed computing resources) are fundamentally the problems of identity management. And yet, efforts by organizations and governments to solve those problems by producing and consuming identity systems may create serious risks to freedom and privacy. Thus the implementation and maintenance of identity management systems raises important public policy issues. The identity management systems (the IMS-s) often tend to require more information from the consumers than would otherwise be necessary for the authentication purposes. The typical choice being analyzed in IMS is the one between a completely centralized or integrated system (one ID - one password, and a single sign-on) and the one comprising a plethora of (highly) specialized IMS-s (multiple ID-s and passwords). While the centralized system is the most convenient one, it is also likely to require too much personal information about the users, which may infringe on their rights to privacy and which definitely will result in serious damage should this personal information be stolen and/or abused. When more than two IMS-s interconnect (more of a practical side with various types of commercial values), they share the private information with each other, thus increasing consumers’ exposure to possible information misuse. It is thus rather obvious that the public policy plays an important role to maintain the structure of identity management systems ensuring the existence of a sound balance between the authentication requirements and consumers’ rights to privacy. The focus of this paper is on investigating this type of tradeoff by employing a theoretical framework with agents whose utility depends on the amount of private information revealed, and on making policy recommendations related to the issue of interconnection between alternative IMS-s. Our model derives optimal process of interconnection between IMS-s in the simple case of three IMS-s, then generalizing it to the case of more than three firms. The socially optimal outcome of the interconnection process in our model implies encouraging the interconnection between smaller rather than larger IMS-s.

Suggested Citation

  • Repkine, Alexandre & Hwang, Junseog, 2004. "A Network-Economic Policy Study of Identity Management Systems and Implications for Security and Privacy Policy," MPRA Paper 7850, University Library of Munich, Germany.
  • Handle: RePEc:pra:mprapa:7850
    as

    Download full text from publisher

    File URL: https://mpra.ub.uni-muenchen.de/7850/1/MPRA_paper_7850.pdf
    File Function: original version
    Download Restriction: no

    References listed on IDEAS

    as
    1. Nicholas Economides, 1997. "The Economics of Networks," Brazilian Electronic Journal of Economics, Department of Economics, Universidade Federal de Pernambuco, vol. 1(0), December.
    2. Olivero, Nadia & Lunt, Peter, 2004. "Privacy versus willingness to disclose in e-commerce exchanges: The effect of risk awareness on the relative role of trust and control," Journal of Economic Psychology, Elsevier, vol. 25(2), pages 243-262, April.
    3. Howard Kunreuther & Geoffrey Heal, 2002. "Interdependent Security: The Case of Identical Agents," NBER Working Papers 8871, National Bureau of Economic Research, Inc.
    Full references (including those not matched with items on IDEAS)

    More about this item

    Keywords

    Networks; Interconnection; Identity Management; Regulation Policy;

    JEL classification:

    • L25 - Industrial Organization - - Firm Objectives, Organization, and Behavior - - - Firm Performance
    • L14 - Industrial Organization - - Market Structure, Firm Strategy, and Market Performance - - - Transactional Relationships; Contracts and Reputation
    • L51 - Industrial Organization - - Regulation and Industrial Policy - - - Economics of Regulation
    • D78 - Microeconomics - - Analysis of Collective Decision-Making - - - Positive Analysis of Policy Formulation and Implementation
    • D85 - Microeconomics - - Information, Knowledge, and Uncertainty - - - Network Formation

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:pra:mprapa:7850. See general information about how to correct material in RePEc.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: (Joachim Winter) or (Rebekah McClure). General contact details of provider: http://edirc.repec.org/data/vfmunde.html .

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service hosted by the Research Division of the Federal Reserve Bank of St. Louis . RePEc uses bibliographic data supplied by the respective publishers.