DocumentCode
2928239
Title
An agent-based framework for identity management: The unsuspected relation with ISO/IEC 15504
Author
Gateau, Benjamin ; Feltus, Christophe ; Aubert, Jocelyn ; Incoul, Christophe
Author_Institution
Centre for IT Innovation, Centre de Rech. Henri Tudor, Luxembourg City
fYear
2008
fDate
3-6 June 2008
Firstpage
35
Lastpage
44
Abstract
The generalization of open and distributed systems and the dynamics of the environment make Information Systems (IS) and, consequently, its access rights management an increasingly complex problem. Even if support for this activity appears to be well handed by current sophisticated solutions, the definition and the exploitation of an access rights management framework appropriately adapted for a company remain challenging. This statement is explained mainly by the continuous growth of the diversity of stakeholderspsila positions and by the criticality of the resources to protect. The SIM project, which stands for ldquoSecure Identity Managementrdquo, addresses this problem. The objectives of our paper are twofold. First, to make rights management align closer to business objectives by providing an innovative approach that focuses on business goals for defining access policy. The ISO/IEC 15504 process-based assessment model has been preferred for that research. Indeed, the structured framework that it offers for the description of activities allows for the establishment of meaningful links with responsibilities concepts. Secondly, to automate the deployment of policies through the company IT infrastructurepsilas components and devices by defining a multi-agent system architecture that provides autonomy and adaptability. Free and open source components have been used for the prototyping phase.
Keywords
IEC standards; ISO standards; authorisation; information systems; innovation management; multi-agent systems; open systems; ISO/IEC 15504; IT infrastructure component; access rights management; business goal; distributed system; information system; innovative approach; multiagent system architecture; open system; secure identity management; Environmental management; IEC standards; ISO standards; Identity management systems; Innovation management; Management information systems; Multiagent systems; Permission; Project management; Protection; Identity Management; Multi-agent architecture; Policy Engineering; Responsibility model;
fLanguage
English
Publisher
ieee
Conference_Titel
Research Challenges in Information Science, 2008. RCIS 2008. Second International Conference on
Conference_Location
Marrakech
Print_ISBN
978-1-4244-1677-6
Electronic_ISBN
978-1-4244-2273-9
Type
conf
DOI
10.1109/RCIS.2008.4632091
Filename
4632091
Link To Document