Title :
An agent-based framework for identity management: The unsuspected relation with ISO/IEC 15504
Author :
Gateau, Benjamin ; Feltus, Christophe ; Aubert, Jocelyn ; Incoul, Christophe
Author_Institution :
Centre for IT Innovation, Centre de Rech. Henri Tudor, Luxembourg City
Abstract :
The generalization of open and distributed systems and the dynamics of the environment make Information Systems (IS) and, consequently, its access rights management an increasingly complex problem. Even if support for this activity appears to be well handed by current sophisticated solutions, the definition and the exploitation of an access rights management framework appropriately adapted for a company remain challenging. This statement is explained mainly by the continuous growth of the diversity of stakeholderspsila positions and by the criticality of the resources to protect. The SIM project, which stands for ldquoSecure Identity Managementrdquo, addresses this problem. The objectives of our paper are twofold. First, to make rights management align closer to business objectives by providing an innovative approach that focuses on business goals for defining access policy. The ISO/IEC 15504 process-based assessment model has been preferred for that research. Indeed, the structured framework that it offers for the description of activities allows for the establishment of meaningful links with responsibilities concepts. Secondly, to automate the deployment of policies through the company IT infrastructurepsilas components and devices by defining a multi-agent system architecture that provides autonomy and adaptability. Free and open source components have been used for the prototyping phase.
Keywords :
IEC standards; ISO standards; authorisation; information systems; innovation management; multi-agent systems; open systems; ISO/IEC 15504; IT infrastructure component; access rights management; business goal; distributed system; information system; innovative approach; multiagent system architecture; open system; secure identity management; Environmental management; IEC standards; ISO standards; Identity management systems; Innovation management; Management information systems; Multiagent systems; Permission; Project management; Protection; Identity Management; Multi-agent architecture; Policy Engineering; Responsibility model;
Conference_Titel :
Research Challenges in Information Science, 2008. RCIS 2008. Second International Conference on
Conference_Location :
Marrakech
Print_ISBN :
978-1-4244-1677-6
Electronic_ISBN :
978-1-4244-2273-9
DOI :
10.1109/RCIS.2008.4632091