• DocumentCode
    3391329
  • Title

    Modeling the Federal User Identity, Credential, and Access Management (ICAM) decision space to facilitate secure information sharing

  • Author

    Smith, Thomas C. ; Vachino, Maria E. ; John, Anil ; Wu, Chi Y. ; Obremski, Christopher D. ; Higa-Smith, Karyn

  • Author_Institution
    Appl. Phys. Lab., Johns Hopkins Univ., Laurel, MD, USA
  • fYear
    2010
  • fDate
    8-10 Nov. 2010
  • Firstpage
    56
  • Lastpage
    62
  • Abstract
    Providing the right information to the right person at the right time is critical, especially for emergency response and law enforcement operations. Accomplishing this across sovereign organizations while keeping resources secure is a formidable task. What is needed is an access control solution that can break down information silos by securely enabling information sharing with non-provisioned users in a dynamic environment. Multiple government agencies, including the Department of Homeland Security (DHS) Science and Technology Directorate (S&T) are currently developing Attribute-Based Access Control (ABAC) solutions to do just that. ABAC supports cross-organizational information sharing by facilitating policy-based resource access control. The critical components of an ABAC solution are the governing organizational policies, attribute syntax and semantics, and authoritative sources. The policies define the business objectives and the authoritative sources provide critical attribute attestation, but syntactic and semantic agreement between the information exchange endpoints is the linchpin of attribute sharing. The Organization for the Advancement of Structured Information Standards (OASIS) Security Assertion Markup Language (SAML) standard provides federation partners with a viable attribute sharing syntax, but establishing semantic agreement is an impediment to ABAC efforts. This critical issue can be successfully addressed with conceptual modeling. S&T is sponsoring the following research and development effort to provide a concept model of the User Identity, Credential, and Access Management decision space for secure information sharing.
  • Keywords
    authorisation; biometrics (access control); data models; electronic data interchange; legislation; peer-to-peer computing; Homeland Security Department; attribute based access control; data modeling; federal user identity; information exchange; information sharing security; law enforcement; security assertion markup language; structured information standard; user access management; user credential; Access control; Contracts; Government; Object recognition; Semantics; Standards organizations; ABAC; DHS; ICAM; access control; data modeling;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Technologies for Homeland Security (HST), 2010 IEEE International Conference on
  • Conference_Location
    Waltham, MA
  • Print_ISBN
    978-1-4244-6047-2
  • Type

    conf

  • DOI
    10.1109/THS.2010.5655096
  • Filename
    5655096