A hybrid multi-application authentication and authorization model using Multi-Agent System and PKI

  • Authors:
  • Somchart Fugkeaw;Piyawit Manpanpanich;Sekpon Juntapremjitt

  • Affiliations:
  • Thai Digital ID Co., Ltd., Bangkok, Thailand;Thai Digital ID Co., Ltd., Bangkok, Thailand;Whitehat Certified Co., Ltd., Bangkok, Thailand

  • Venue:
  • AsiaCSN '07 Proceedings of the Fourth IASTED Asian Conference on Communication Systems and Networks
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Authentication, Authorization, Accountability (AAA) is always required for a good access control system. This paper proposes a Single Sign-On (SSO) model that serves the AAA property with the activity-based policy. The trust in this approach is enabled by the use of public key infrastructure (PKI) which is applied for client two-factor authentication and secures the infrastructure. We introduce the preventive activity-based authorization policy for dynamic user privilege controls. It helps prevent successive unauthorized requests in a formal manner. At the core, we apply the Multi-Agent System (MAS) concept to facilitate the authentication and the authorization process in order to work with multi-applications and multi-clients more dynamically and efficiently. The agent system functions when each client requests to sign on and it is responsible for validating a client certificate, granting an access role to the client, and controlling a concurrent use of applications.