• DocumentCode
    3217814
  • Title

    An SSO-Capable Distributed RBAC Model with High Availability across Administrative Domain

  • Author

    Juntapremjitt, Sekpon ; Fugkeaw, Somchart ; Manpanpanich, Piyawit

  • Author_Institution
    Whitehat Certified Co., Ltd., Bangkok
  • fYear
    2008
  • fDate
    25-28 March 2008
  • Firstpage
    121
  • Lastpage
    126
  • Abstract
    This paper proposes a novel design and implementation of distributed RBAC (dRBAC) and single sign-on (SSO) system that spans over multiple administrative domains with high availability. The core idea is based on multi-agent systems (MAS) technique owing to its modularity, autonomy, distributedness, flexibility, and scalability. All agents serve their specific purposes. Leveraging agents simplifies high availability. PKI is used for trust enablement between intra- and inter-domain agent communications. The security assertion markup language (SAML) is adopted for supporting the exchange of authentication and authorization information in the architecture. The approach supports strong two-factor authentication with X.509 digital certificate. The authorization scheme is based on the privilege management infrastructure (PMI). Finally, we reported our extended implementation status and demonstrated that our proposed model is efficient and flexible to implement in the multiple SSO and PKI domains.
  • Keywords
    authorisation; certification; distributed processing; multi-agent systems; public key cryptography; X.509 digital certificate; administrative domain; authorization; autonomy; distributed RBAC model; flexibility; information exchange; interdomain agent communication; intradomain agent communication; modularity; multiagent system; privilege management infrastructure; public key infrastructure; scalability; security assertion markup language; single sign-on system; trust enablement; two-factor authentication; Access control; Authentication; Authorization; Availability; Communication system security; Environmental management; Information security; Mobile communication; Multiagent systems; Protocols; Privilege Management Infrastructure; SAML; Single Sign-On; X.509 Public Key Certificate; XACML; dRBAC;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications - Workshops, 2008. AINAW 2008. 22nd International Conference on
  • Conference_Location
    Okinawa
  • Print_ISBN
    978-0-7695-3096-3
  • Type

    conf

  • DOI
    10.1109/WAINA.2008.175
  • Filename
    4482900