VLDB 2026 Research / reviewers in the wild / expert
Christophe Feltus
dblp:41/2512
· DBLP profile ↗
32ranked-venue papers
16as first author
4since 2021 · last 2025
0000-0002-7182-8185ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 8 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 11 · 6 first-author · 2 since 2021Software engineering, systems software and programming languages · 7 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 4 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Digital Twin Micro-Services Architecture to Support a Scenario-based Integration of Smart Mobility Services and SimulationsabstractThis paper proposes a microservices-based digital twin architecture for flexible, scalable, and real-time integration of smart mobility services in urban centers.By decoupling functions into modular services embedded in scenario-driven simulations, the digital twin overcomes limitations of monolithic systems, enhancing adaptability and interoperability.Preliminary results demonstrate its effectiveness for dynamic urban mobility management. Damien Nicolas, Christophe Feltus, Ruben Antonio de Jesus Marques |
FedCSIS | 2 |
| 2023 | Towards Enhancing Open Innovation Efficiency: A Method for Ontological Integration of BPMN and EMMOabstractThe process of open innovation based on advanced materials involves the collaborative sharing of knowledge, ideas, and resources among different organisations, such as academic institutions, businesses, and government agencies.It is suggested that Business Process Modelling and Notations (BPMN) and Elementary Multiperspective Material Ontology (EMMO) be closely integrated to accelerate the development of new materials and technologies and address complex material challenges.In this paper, we examine the integration of EMMO and BPMN through an initial investigation to streamline workflows, enhance communication, and improve the understanding of materials knowledge.We propose a four-step approach to integrate both ontologies, which involves ontology alignment, mapping, integration, and validation.Our approach supports faster and more cost-effective research and development processes, leading to more effective and innovative solutions. Christophe Feltus, Damien Nicolas, Carlos Kavka, Djamel Khadraoui, Salim Belouettar, Natalia A. Konchakova, Heinz A. Preisig, Peter Klein 0001 |
FedCSIS | 1 |
| 2022 | A CNN-Based Semi-supervised Learning Approach for the Detection of SS7 Attacks
Orhan Ermis, Christophe Feltus, Qiang Tang 0001, Alexandre De Oliveira, Duy Cu Nguyen, Alain Hirtzig |
ISPEC | 2 |
| 2022 | Towards a Lightweight Model-driven Smart-city Digital Twin
Jean-Sébastien Sottet, Pierre Brimont, Christophe Feltus, Benjamin Gâteau, Jean François Merche |
MODELSWARD | 3 |
| 2019 | An integrated conceptual model for information system security risk management supported by enterprise architecture management
Nicolas Mayer, Jocelyn Aubert, Eric Grandry, Christophe Feltus, Elio Goettelmann, Roel J. Wieringa |
Softw. Syst. Model. | 4 |
| 2018 | Value CoCreation (VCC) Language Design in the Frame of a Smart Airport Network Case StudyabstractThe design and engineering of collaborative networks and business ecosystems is a discipline that requires an outstanding and upfront attention of the value cogenerated among the parties involved in the business exchanges of these networks. Understanding this value cocreation is undoubtedly paramount, first to adequately sustain the design and the development of the information system that brings about this value, second, to support the communication between the information system designers, and third to allow discovering new cocreation opportunities amongst the networks companies. In that context, we proposed an abstract language (metamodel) that structures, and provides an explanatory semantics to, the cocreation of value between information system designers, allowing a better definition of the collaboration and of each one value propositions. The design of this language is achieved in the frame of the design science theory and accordingly follows an iterative improvement approach based on real case studies from practitioners. This paper introduces the second iteration of the language based on a real case in a Smart Airport Network. Christophe Feltus, Henderik A. Proper, Andreas Metzger, Juan Carlos Garcia Lopez, Rodrigo Castiñeira |
AINA | 1 |
| 2018 | Towards a Language to Support Value Cocreation: An Extension to the ArchiMate Modeling FrameworkabstractValue cocreation is gaining momentum as organizations' underlying business logic and encompasses tools and techniques for discovering new valuable and necessary artefacts to support inter-organizational and network-centric business activities.To cocreate value, organizations must talk to each other using a clear and easy to use language.In the course of the ValCoLa (Value Cocreation Language) project, we aim at elaborating such language.To that end, in previous work, we developed a value cocreation metamodel based on three dimensions: the nature of the value, the object concerned by the value and the method to cocreate value.In this paper, we first extend ArchiMate to the domain of value cocreation to provide our metamodel with a dedicated modeling language.Second, we illustrate the language with a case study from the financial sector.I. Christophe Feltus, Henderik A. Proper, Mohammad Kazem Haki |
FedCSIS | 1 |
| 2018 | Solving the trust issues in the process of transportation of dangerous goods by using blockchain technologyabstractThe issues of trust in the area of supply chain management are an immense concern among the stakeholders cooperating in the supply chain. For a sustainable process of transportation, efficient information sharing is considered crucial. The models that serve as a base for the current operations have several drawbacks in terms of data security and trust among stakeholders, who share information as part of their cooperation. Information is shared in a paper-based or semi-digitalized way due to the lack of trust or risk of competitive disadvantages in the current systems. This paper aims to analyze the trust issues in supply chain management and propose new ways of improving trust by considering these issues at the design level. Adnan Imeri, Christophe Feltus, Djamel Khadraoui, Nazim Agoulmine, Damien Nicolas |
SIN | 2 |
| 2018 | Coalition-OrBAC: An Agent-Based Access Control Model for Dynamic Coalitions
Iman Ben Abdelkrim, Amine Baïna, Christophe Feltus, Jocelyn Aubert, Mostafa Bellafkih, Djamel Khadraoui |
WorldCIST (1) | 3 |
| 2017 | Conceptualization of an Abstract Language to Support Value Co-CreationabstractCompanies willing to survive the numeric economy are forced to collaborate with each other in order to maximize their co-creation of value.This co-creation exists for many reasons: to sell and acquire information, goods and services, to optimize the quality of procedures, to improve security and privacy, etc.In this paper, we analyze and model value cocreation through three dimensions: the value's nature, the method of value creation, and the business object impacted by the value.By combining these dimensions, we afterwards suggest different types of co-creation schemas, and we propose an abstract language to communicate them.The latter is finally validated by applying the "The Physics of Notations" guidelines. I. Christophe Feltus, Henderik A. Proper |
FedCSIS | 1 |
| 2017 | Model-driven Approach for Privacy Management in Business EcosystemabstractProtection of individuals with regard to the processing of personal data and the free movement of such data constitutes new challenges in terms of privacy management. Although this privacy management ought to be conducted in compliance with national and international regulation, for now we observe that no solution, model or method, fully consider and integrate these new regulations yet. Therefore, in this paper, we propose to tackle this problem through the definition of an expressive privacy metamodel which aims to represent and aggregate the concepts that are relevant to define and to deal with privacy issues, at an organizational level. Secondly, we discuss how this privacy metamodel may support and may help understanding the management of the privacy in enterprises involve in interconnected societies, by integrating the privacy metamodel with the systemic business ecosystem. Christophe Feltus, Eric Grandry, Thomas Kupper, Jean-Noël Colin |
MODELSWARD | 1 |
| 2016 | Towards a Systemic Approach for Information Security Risk ManagementabstractRisk management in the field of information security is most often handled individually by enterprises, taking only a limited view on the influential factors coming from their providers, clients or more globally from their environment. This approach becomes less appropriate in the case of networked enterprises, which tend to form ecosystems with complex influence links. A more holistic approach is needed to take these into account, leading to systemic risk management, i.e. risk management on the entire system formed by the networked enterprises, to avoid perturbations of the ecosystem due to local, individual, decision-making. In this paper, we propose a new meta-model for Information System Security Risk Management (ISSRM), comprising systemic elements as defined in the General Systems Theory. We discuss the design of this new model, highlighting in particular how risk management can be related to a problem-solving approach and the important concepts that are instantiated when taking a systemic approach to ISSRM. Yannick Naudet, Nicolas Mayer, Christophe Feltus |
ARES | 3 |
| 2015 | Alignment of ReMMo with RBAC to manage access rights in the frame of enterprise architectureabstractAligning the business operations with the appropriate IT infrastructure is a challenging and critical activity. Without efficient business/IT alignment, the companies face the risk not to be able to deliver their business services satisfactorily and that their image is seriously altered and jeopardized. Among the many challenges of business/IT alignment is the access rights management which should be conducted considering the rising governance needs, such as taking into account the business actors' responsibility. Unfortunately, in this domain, we have observed that no solution, model and method, fully considers and integrates the new needs yet. Therefore, the paper proposes firstly to define an expressive Responsibility metamodel, named ReMMo, which allows representing the existing responsibilities at the business layer and, thereby, allows engineering the access rights required to perform these responsibilities, at the application layer. Secondly, the Responsibility metamodel has been integrated with ArchiMate® to enhance its usability and benefits from the enterprise architecture formalism. Finally, a method has been proposed to define the access rights more accurately, considering the alignment of ReMMo and RBAC. The research was realized following a design science and action design based research method and the results have been evaluated through an extended proof of concept at the Hospital Center in Luxembourg. Christophe Feltus, Eric Dubois 0001, Michaël Petit |
RCIS | 1 |
| 2015 | Analysis of the impact of ethical issues on the management of the access rightsabstractNowadays, the evolution of the information system (IS) is very fast and companies have to manage a very huge amount of sensitive and critical information. Therefore, the information system managers are urged to accurately design their IS and to provide the accurate access rights to this information. In that regards, although the advantage of this strict definition of the IS, we observe that this evolution also tends to reduce and to limit the employees' personal initiatives to act and to behave for the well-being of the company, especially in the case of professional ethical reasons. In this context, this paper takes up the challenge to show to the information security specialists the importance of addressing ethical issues along the management of the access rights and proposes a model-based technical approach to face this problem. André Rifaut, Christophe Feltus, Slim Turki, Djamel Khadraoui |
SIN | 2 |
| 2014 | Towards an Innovative Systemic Approach of Risk ManagementabstractNowadays, enterprises from different sectors are strongly interconnected and need to interact continuously in order to survive. In this context, the happening of an event (e.g., system failure) in one sector may lead to a serious risk in another. To avoid this, a systemic approach for risk management is required. This approach pursues the objective to foster the accuracy and the reactivity of the risk mitigation and hence minimize the impact and the propagation of the risk and, as a consequence, sustain the initiatives from all economic domains' regulators in risk management. This position paper suggests an innovative solution, which is to be further investigated, to manage cross-sector ICT ecosystem risks using enterprise architecture model. This solution is illustrated with a proof of concept related to the Luxembourgish market. Hervé Cholez, Christophe Feltus |
SIN | 2 |
| 2014 | Towards a HL7 based Metamodeling Integration Approach for Embracing the Privacy of Healthcare Patient Records AdministrationabstractHL7 is a standard developed to support the exchange of information related to the medical field across institutions from the same country or from different countries. This standard provides mainly a framework to sustain the data exchange at the application / technical layer and the thereby minimize the importance of business / organization information. This is contradictory to the arising requirements dictated by the information security governance which claims the access rights to be only provided where there are business justifications. In this context, the paper aims at extending HL7 with a responsibility perspective in order to enhance the access rights considering organization constraints. Therefore, the paper firstly proposes an integration of both models and secondly provides an innovative HL7 XML format which supports new business related information framework defined around the notion of responsibility. Christophe Feltus, Damien Nicolas, Claude Poupart |
SIN | 1 |
| 2013 | Organizational Security Architecture for Critical InfrastructureabstractThe governance of critical infrastructures requires a fail-safe dedicated security management organization. This organization must provide the structure and mechanisms necessary for supporting the business processes execution, including: decision-making support and the alignment of this latter with the application functions and the network components. Most research in this field focuses on elaborating the SCADA system which embraces components for data acquisition, alert correlation and policy instantiation. At the application layer, one of the most exploited approaches for supporting SCADA is built up on multi-agent system technology. Notwithstanding the extent of existing work, no model allows to represent these systems in an integrated manner and to consider different layers of the organization. Therefore, we propose an innovative version of ArchiMate® for multi-agent purpose with the objective to enrich the agent society collaboration and, more particularly, the description of the agent's behavior. Our work is has been illustrated in the context of a critical infrastructure in the field of a financial acquiring/issuing mechanism for card payments. Jonathan Blangenois, Guy Guemkam, Christophe Feltus, Djamel Khadraoui |
ARES | 3 |
| 2013 | Industry program panelabstractThe security of the information owned by the industries is judged as the main concern of these industries' managers, even more than the possibility of the euro zone's breakup or any natural disaster. This statement has been reported by the recent « Global State of Information Security Survey 2013 » published by PwC and CIO Magazine. This observation must be analysed in parallel to a continuous gowning of the worldwide investment in information security, which has been estimated by PwC, up to 500 billion dollars. Despite the great importance given in the information security, it is noted that 71 percent of these managers continue, in the meantime, to trust their information security system, although only 8 percent of them really possess an organisation adapted to the new information risks. Christophe Feltus |
SIN | 1 |
| 2013 | Conviction model for incident reaction architecture monitoring based on automatic sensors alert detectionabstractDynamic distributed wireless networks constitute a critical pillar for the information system. Nonetheless, the openness of these networks makes them very sensitive to external attack such as the DoS. Being able to monitor the conviction level of network components and to react in a short time once an incident is detected is a crucial challenge for their survival. In order to face those problems, research tends to evolve towards more dynamic solutions that are able to detect and validate network anomalies and to adapt themselves in order to retrieve a secure configuration. In this position paper, we complete our previous works and make the assignment of functions to agents more contextual. Our approach considers the concept of agent responsibility that we assigned dynamically to agent and that we exploit in order to analyze the level of "conviction" in the component. In this current paper, we provide an insight of the architecture without depicting the assignment mechanism neither the conviction calculation. Christophe Feltus, Djamel Khadraoui |
SIN | 1 |
| 2013 | On designing automatic reaction strategy for critical infrastructure SCADA systemabstractThe huge amount of information managed by Critical Infrastructure (CI) argues for the support of SCADA systems which behave as very complex and sophisticated tools. These latter support CI operators in monitoring and governing the system security by elaborating the operational policies amongst the architecture components. In [1] and [2] we have exploited enterprise architecture management tool to construct an integrated SCADA metamodel dedicated to these components' artefacts and structured according to (1) three layers of abstraction, namely: Organization, Application, and Technical layer and (2) two semantically consistent types of policies: the Permissive Policy and the Cognitive Policy. The results of the SCADA modelling and policy engineering approach constitute, as illustrated through the CockpitCI project case study, a global analytical tool for the SCADA operators which may rely on a rational and unified component security based architecture to continuously monitor and manipulate the policy attributes acknowledging their impact on the whole CI system. In this poster, we illustrate how the metamodel for SCADA components is used together with the method for policy scheme identification to support automatic reaction strategy. Christophe Feltus, Djamel Khadraoui |
SIN | 1 |
| 2013 | Metamodel for reputation based agents system: case study for electrical distribution SCADA designabstractSCADA systems are urged to face more and more complex critical situation and thereby, need to continuously evolve towards integrated decision making capability driven by fancy reaction strategy. The current research stream in that field, aims, accordingly, to foster the smartness of the field equipment and actuators, which predominately exist under the concept of agents. Those agents are governed by policies that while dictating the agent behavior, depending on the agent roles and the context of evolution, also confer to the latter the latitude to react based on their own perception of the evolving environment. This agent ability is referring to as the agent smartness and is strongly determined by, and depending on, the trust perceived by the agent of its environment. Actual work related to agents tends to consider that agents evolve and are organized in systems. There exist some models for representing how these agents are organized at a high level, models for representing how they are spread in the networks, models to represent how they communicate to each other, and so forth. However, as far as we know, no model exists that integrates all of the above models. Therefore, we do believe that such an integrated model could have many advantages like e.g. to know the impact from the action from one layer to another, to decide which action on a component has the most important impact on a set of other components, to identify the most critical component for an infrastructure, to align the agent system with the corporate objective and to tailor it accordingly. Therefore, we have decided to frame an innovative version of ArchiMate® for the multi-agent purpose with the objective to enrich the agent society collaborations and, more particularly, the description of the agent behavior endorsed in the policy component and using a reputation based trust model to improve the reliability, termed ARMAN. Our work has been illustrated in the frame of a critical infrastructure in the field of electrical power distribution which is a highly sensitive research topic. Guy Guemkam, Jonathan Blangenois, Christophe Feltus, Djamel Khadraoui |
SIN | 3 |
| 2013 | Critical Infrastructures Governance Exploring SCADA Cybernetics through Architectured Policy SemanticabstractSCADA-systems are very complex, sophisticated and integrated systems which support people in monitoring and governing the huge volumes of knowledge engendered by critical infrastructures (industry, energy, transport, and healthcare). These systems are elaborated upon a colossal range of precontrived components which need to interact thoroughly with each other although, a priori, they all use heterogeneous technologies and protocols, they behave unevenly through the SCADA architecture, and they are all located in miscellaneous corners of the production system. Furthermore, these components interact, amongst other, by means of policies which formulate the reasoning for component behaviour in terms of expecting actions realization or in terms of accessed information. This paper explores these policies' semantic through a unified component modelling approach with the aim of providing a homogeneous and coherent framework, adapted for the governance of the system by all SCADA and non-SCADA operators. Djamel Khadraoui, Christophe Feltus |
SMC | 2 |
| 2012 | Enhancing the ArchiMate® standard with a responsibility modeling language for access rights managementabstractIn this paper, we describe an innovative approach for aligning the business layer and the application layer of ArchiMate to ensure that applications manage access rights consistently with enterprise goals and risk tolerances. The alignment is realized by using the responsibility of the employees, which we model using ReMoLa. The main focus of the alignment targets the definition and the assignment of the access rights needed by the employees according to business specification. The approach is illustrated and validated with a case study in a municipal hospital in Luxembourg. Christophe Feltus, Eric Dubois 0001, Henderik A. Proper, Iver Band, Michaël Petit |
SIN | 1 |
| 2011 | Dynamic Responsibilities Assignment in Critical Electronic Institutions - A Context-Aware Solution for in Crisis Access Right ManagementabstractNowadays critical IT infrastructures constitute the pillars of our economy. Being able to react quickly and in real time is a crucial challenge for the security officers in charge of maintaining those infrastructures operationally. Our state of the art in this field has highlighted that many architectures exist to dynamically support the reaction after the detection of an incident infrastructure. Those architectures are mostly elaborated based on a multi-agent system approach that offers the possibility to work in a decentralized and heterogeneous environment. However, in the meantime, we have observed that those architectures are based on a static assignment of functions to agents and that, as a consequence, isolating an agent or breaking the communication channel between two of them could create serious damage on the management of the crisis. In this paper, we propose an innovative approach for making the assignment of functions to agents in the critical architecture dynamic. Our approach exploits the concept of agent responsibility that we assign dynamically to those agents depending on the crisis type and severity. Simultaneously we explain the dynamic assignment of the access rights necessary to perform the obligation linked to these new responsibilities. This dynamic assignment of responsibilities is illustrated based on the architecture defined in the ReD project. Cédric Bonhomme, Christophe Feltus, Michaël Petit |
ARES | 2 |
| 2011 | ReMoLa: Responsibility model language to align access rights with business process requirementsabstractAccess controls is an important IT security issue and has accordingly been a huge research topic for the last decade. Many models and role engineering methods have been provided since then, and RBAC has appeared to be one of the most significant contributions. In parallel to those developments, new requirements have appeared in the field of IT governance and they provide new constraints for the elicitation of access control policies. One of those requirements is to have access rights strictly aligned with the business process and to have the responsibility of the employees involved in those processes strictly defined and suitably assigned to the employee. RBAC doesn't permit to integrate these new requirements. In this paper we propose a responsibility modeling language to align access rights with business processes requirements. To achieve that, our approach uses the concept of employees' responsibility as a means to bridge the gap through frameworks from the business layer down to frameworks from the technical layer. Christophe Feltus, Michaël Petit, Eric Dubois 0001 |
RCIS | 1 |
| 2010 | A Security Decision-Reaction Architecture for Heterogeneous Distributed NetworkabstractThe main objective of this paper is to provide a global decision-reaction architectural built on the requirements for a reaction after alert detection mechanisms in the frame of information systems security and more particularly applied to telecom infrastructures security. These infrastructures are distributed in nature, therefore the architecture is elaborated using the multi-agents system that provides the advantages of autonomous and interaction facilities, and has been associated to the ontoBayes model for decision support mechanism. This model helps agents to make decisions according to preference values and is built upon ontology based knowledge sharing, bayesian networks based uncertainty management and influence diagram based decision support. The Multi-Agent System decision-reaction architecture is developed in a distributed perspective and is composed of three basic layers: low level, intermediate level and high level. The proposed approach has been illustrated based on the network architecture for heterogeneous mobile computing developed by the BARWAN project. Accordingly: the Building Area constitutes the low level and aims to be the interface between the main architecture and the targeted infrastructure. The Campus-Area is the intermediate level responsible of correlating the alerts coming from different domains of the infrastructure and to smartly deploy the reaction actions. Christophe Feltus, Djamel Khadraoui, Jocelyn Aubert |
ARES | 1 |
| 2010 | A multi-agent based decision mechanism for incident reaction in telecommunication networkabstractThe paper provides a global architectural and decision support solution for a reaction after alert detection mechanisms in the frame of information systems security applied to telecom infrastructures. Therefore, the architecture is developed in a distributed perspective and is composed of three basic layers: the low level that constitutes the interface between the architecture and the infrastructure. The intermediate level that is responsible of correlating the alerts coming from different domains of the infrastructure and to deploy the reaction actions. The architecture is elaborated using a MAS associated to the OntoBayes model for decision mechanism. This model helps agents to make decisions according to preference values and is built upon ontology based knowledge sharing, Bayesian networks based uncertainty management and influence diagram. The major novelty of this Decision Support System is the layered view of the infrastructure thanks to MAS architecture, which enables the decision making with different levels of knowledge. Cédric Bonhomme, Christophe Feltus, Djamel Khadraoui |
AICCSA | 2 |
| 2009 | Methodology to Align Business and IT Policies: Use Case from an IT CompanyabstractGovernance of IT is becoming more and more necessary in the current financial economic situation. One declination of that statement is the definition of corporate and IT policies. To improve that matter, the paper has for objective to propose a methodology for defining policies that are closer to the business processes, and based on the strict definition of a responsibility model that clarify all actorpsilas responsibility. This responsibility model is mainly defined based on the three concepts of capability, the accountability and the commitment. The methodology is illustrated and validated based on a case study conducted in an IT company. Christophe Feltus, Christophe Incoul, Jocelyn Aubert, Benjamin Gâteau, André Adelsbach, Marc Camy |
ARES | 1 |
| 2009 | Building a Responsibility Model Including Accountability, Capability and CommitmentabstractThis paper aims at building a responsibility model based on the concepts of accountability, capability and commitment. The model's objectives are firstly to help organizations for verifying the organizational structure and detecting policy problems and inconsistency. Secondly, the paper brings up a conceptual framework to support organization for defining their corporate, security and access control policies. Our work provides a preliminary review of the researches performed in that field and proposes, based on the analyses, an UML responsibility model and a definition of all its concepts. Thereafter, to propose a formal representation of the model, we have selected the suitable language and logic system. The analyze highlights that an important variable is whether the responsibility is perceived at a user or at a company level. Christophe Feltus, Michaël Petit |
ARES | 1 |
| 2009 | Building a responsibility model using modal logic - towards Accountability, Aapability and Commitment conceptsabstractThis paper aims at building a responsibility model based on the concepts of accountability, capability and commitment. This model's objective is, firstly, to help organizations verify the organization structure and detect policy problems and inconsistencies, and secondly, to provide a conceptual framework to support them in defining their corporate, security and access control policies. Our work provides a preliminary review of the research performed in that field and proposes, based on the observations, an UML responsibility model and a definition for all its components. Thereafter, we suggest and explain a deontological logic formalization of the most significant concepts. To achieve that, our innovation stands in the adaptation of the traditional threefold classification from the alethic logic to an adapted threefold classification that targets ldquoresponsibilityrdquo and based upon which commitment is somewhat refined. Christophe Feltus, Michaël Petit |
AICCSA | 1 |
| 2008 | If only I can trust my police! SIM : An agent-based audit solution of access right deployment through open networkabstractDynamic and evolved environment make the Information Systems (IS), and consequently access rights to its components, always more complex to define and to manage. To bring up a contribution for improving that matter, our paper’s first objective is to realize the development of an automated deployment of policies from an administrative platform that encompasses business requirements down to infrastructure’s components and devices. This objective is achieved by adapting the XACML OASIS framework [22] and by formalizing a protocol for information exchange through different components of a multi-agent system. The second paper’s objective aims at providing guaranties that defined and deployed access rights are continuously aligned with business requirements. This objective is completed by complementary developments that aim to perform a systematic and/or on-demand audit of the effective rights against the desired ones. This second objective is achieved by adding new functionality to the proposed agents architecture and by adapting the protocol accordingly. Practically, this research has been performed in the framework of the SIM [1] project and has privileged free and open source components for the prototyping phase. Christophe Incoul, Benjamin Gâteau, Jocelyn Aubert, Nicolas Bounoughaz, Christophe Feltus |
CRiSIS | 5 |
| 2008 | An agent-based framework for identity management: The unsuspected relation with ISO/IEC 15504abstractThe generalization of open and distributed systems and the dynamics of the environment make Information Systems (IS) and, consequently, its access rights management an increasingly complex problem. Even if support for this activity appears to be well handed by current sophisticated solutions, the definition and the exploitation of an access rights management framework appropriately adapted for a company remain challenging. This statement is explained mainly by the continuous growth of the diversity of stakeholderspsila positions and by the criticality of the resources to protect. The SIM project, which stands for ldquoSecure Identity Managementrdquo, addresses this problem. The objectives of our paper are twofold. First, to make rights management align closer to business objectives by providing an innovative approach that focuses on business goals for defining access policy. The ISO/IEC 15504 process-based assessment model has been preferred for that research. Indeed, the structured framework that it offers for the description of activities allows for the establishment of meaningful links with responsibilities concepts. Secondly, to automate the deployment of policies through the company IT infrastructurepsilas components and devices by defining a multi-agent system architecture that provides autonomy and adaptability. Free and open source components have been used for the prototyping phase. Benjamin Gâteau, Christophe Feltus, Jocelyn Aubert, Christophe Incoul |
RCIS | 2 |