Title | Design and development of the dynamic DRBAC model using PMI and xacml-based authorization |
Publication Type | Journal Article |
Year of Publication | 2009 |
Authors | Fugkeaw, S, Manpanpanich, P, Juntapremjitt, S |
Journal | Journal of Digital Information Management |
Volume | 7 |
Issue | 2 |
Pagination | 63 - 73 |
Date Published | 2009 |
Keywords | Drbac authorization, Privilege Management Infrastructure, SAML, X.509 public key certificate, XACML |
Abstract | In the distributed computing environment, collaboration and resource sharing among several organizations are subjects of concern. Well-established authentication and authorization are thus vital. This paper proposes a novel design and implementation of Distributed RBAC (DRBAC) and Single Sign-On (SSO) system that spans over multiple administrative domains. Our key idea is based on Multi-Agent Systems (MAS) technique owing to its modularity, autonomy, distributedness, flexibility, and scalability. All agents serve their specific purposes. We use PKI technology to secure both intra- and interdomain agents communication as well as to establish trust relationships. The Security Assertion Markup Language (SAML) is adopted to support the exchange of authentication and authorization information in the architecture. The authorization scheme is based on the Privilege Management Infrastructure (PMI). In addition, we incorporate the XACML authorization concept into the MAS engine to support the relying parties or organizations whose their access control systems are written in XACML policy. Finally, we reported our extended implementation status and introduce the multi-instance processing technique to enhance the performance of the overall system. |
URL | http://www.scopus.com/inward/record.url?eid=2-s2.0-70350666673&partnerID=40&md5=f54e5a65269f08ac0f6dda7b45a823c1 |