Design and development of the dynamic DRBAC model using PMI and xacml-based authorization

TitleDesign and development of the dynamic DRBAC model using PMI and xacml-based authorization
Publication TypeJournal Article
Year of Publication2009
AuthorsFugkeaw, S, Manpanpanich, P, Juntapremjitt, S
JournalJournal of Digital Information Management
Volume7
Issue2
Pagination63 - 73
Date Published2009
KeywordsDrbac authorization, Privilege Management Infrastructure, SAML, X.509 public key certificate, XACML
Abstract

In the distributed computing environment, collaboration and resource sharing among several organizations are subjects of concern. Well-established authentication and authorization are thus vital. This paper proposes a novel design and implementation of Distributed RBAC (DRBAC) and Single Sign-On (SSO) system that spans over multiple administrative domains. Our key idea is based on Multi-Agent Systems (MAS) technique owing to its modularity, autonomy, distributedness, flexibility, and scalability. All agents serve their specific purposes. We use PKI technology to secure both intra- and interdomain agents communication as well as to establish trust relationships. The Security Assertion Markup Language (SAML) is adopted to support the exchange of authentication and authorization information in the architecture. The authorization scheme is based on the Privilege Management Infrastructure (PMI). In addition, we incorporate the XACML authorization concept into the MAS engine to support the relying parties or organizations whose their access control systems are written in XACML policy. Finally, we reported our extended implementation status and introduce the multi-instance processing technique to enhance the performance of the overall system.

URLhttp://www.scopus.com/inward/record.url?eid=2-s2.0-70350666673&partnerID=40&md5=f54e5a65269f08ac0f6dda7b45a823c1

Collaborative Partner

Institute of Electronic and Information Technology (IEIT)

Collaborative Partner

Collaborative Partner