Title :
If only I can trust my police! SIM : An agent-based audit solution of access right deployment through open network
Author :
Incoul, Christophe ; Gateau, Benjamin ; Aubert, Jocelyn ; Bounoughaz, Nicolas ; Feltus, Christophe
Author_Institution :
Centre for IT Innovation, Centre de Recherche Public Henri Tudor, Luxembourg City
Abstract :
Dynamic and evolved environment make the Information Systems (IS), and consequently access rights to its components, always more complex to define and to manage. To bring up a contribution for improving that matter, our paperpsilas first objective is to realize the development of an automated deployment of policies from an administrative platform that encompasses business requirements down to infrastructurepsilas components and devices. This objective is achieved by adapting the XACML OASIS framework and by formalizing a protocol for information exchange through different components of a multi-agent system. The second paperpsilas objective aims at providing guaranties that defined and deployed access rights are continuously aligned with business requirements. This objective is completed by complementary developments that aim to perform a systematic and/or on-demand audit of the effective rights against the desired ones. This second objective is achieved by adding new functionality to the proposed agents architecture and by adapting the protocol accordingly. Practically, this research has been performed in the framework of the SIM project and has privileged free and open source components for the prototyping phase.
Keywords :
authorisation; information systems; multi-agent systems; open systems; protocols; XACML OASIS framework; access right deployment; administrative platform; business requirement; extended access control markup language; information exchange; information system; multiagent-based audit solution; open network; open source component; protocol; prototyping phase; secure identity management; Access protocols; Environmental management; Identity management systems; Innovation management; Internet; Management information systems; Multiagent systems; Permission; Prototypes; Technological innovation; Identity Management; Policy audit; Responsibility model; multi agent architecture;
Conference_Titel :
Risks and Security of Internet and Systems, 2008. CRiSIS '08. Third International Conference on
Conference_Location :
Tozeur
Print_ISBN :
978-1-4244-3309-4
DOI :
10.1109/CRISIS.2008.4757467