Wednesday, March 31, 2010

Back to Blogging

After a long period of inactivity, due to several internal and external factors, here I am ready to write about Roles and Identity Management again!

It has been almost a year since my last post. During this period, I haven’t had a lot of time for things like the blog, and this was a big mistake for various reasons. One of these being that since Engiweb Security is an engineering-focused organization that has not given a lot of attention to marketing, this blog can (among other IdM related considerations) try to support efforts to raise its profile and properly position Engiweb Security in the marketplace.

While I was gone, there have been a number of notable movements in the market, and many of the latest announcements involve IAM: Oracle swallowing up SUN, Gartner taking over Burton Group, etc…
In the meantime it looks like the Role Management bandwagon is as hot as when I started neglecting this blog months ago.
Furthermore, Engiweb Security is in the process of better positioning its offer in order to avoid possible miscommunications or challenges to our potential clients.

In a week or so, I’ll post a blog about the evolution of IDEAS (our Identity &Access Governance solution) and our latest partnership deals.
I also still plan on posting articles about current IdM debates. For instance, I find the ABAC-RBAC heated debate very exciting, and it still arouses my curiosity. BTW why are they still using the “Role Explosion” hackneyed and false excuse to justify that RBAC is not usable?

Anyway… back to us! For now, the Engiweb team has published new academic papers for the security community, describing the conceptual model used in the IDEAS solution in detail.
  • A. Colantonio, R. Di Pietro, A. Ocello, and N. V. Verde. “Taming Role Mining Complexity in RBAC”. Computers & Security, Challenges for Security, Privacy & Trust (special issue), Elsevier, 2010.
  • A. Colantonio, R. Di Pietro, A. Ocello, and N. V. Verde. “ABBA: Adaptive Bicluster-Based Approach to Impute Missing Values in Binary Matrices”. In Proceedings of the 25th ACM Symposium on Applied Computing, SAC '10, Sierre, Switzerland, March 2010.
  • A. Colantonio, R. Di Pietro, A. Ocello, and N. V. Verde. “A Formal Framework to Elicit Roles with Business Meaning in RBAC Systems”. In Proceedings of the 14th ACM Symposium on Access Control Models and Technologies, SACMAT '09, Stresa, Italy, June 2009.
If you are interested in receiving the full texts, please send me an e-mail: my surname at eng dot it.

Thursday, April 30, 2009

In Munich, for "European Identity Conference 09" next week?

The Kuppinger Cole European Identity Conference 09 will take place on May 05 - 08, 2009 in Munich - Germany. It is Europe's largest Conference on Identity & Access Management with more than 50 exhibitors.

This event is a great networking opportunity for smart, innovative, and forward thinking people to get together to learn about and discuss today's most significant technology topics on IAM.

Complete details are available here, so come visit Engiweb Security's booth, or attend one of the three panels were we will be speaking.

Also, Engineering Ingegneria Informatica will be presenting a case study based on our IDEAS Platform at 15:00 on Tuesday, May 5. It will be a highly informative speech, so I hope you will attend.
I hope to see you next week.

Wednesday, January 7, 2009

Alessandro strikes again!

Two new Technical Papers, “Mining Stable Roles in RBAC”, and “A Probabilistic Bound on the Basic Role Mining Problem and its Applications” have been recently accepted and will be presented, by my colleague Alessandro Colantonio, at the coming IFIP/SEC-2009- 24th IFIP International Information Security Conference, Pafos, Cyprus, May 18-20, 2008.

I am not an expert in the used theoretical and mathematical concepts, but I find the global effort to minimize complexity very insightful. Clearly, keeping the number of different roles sufficiently small is an important aspects. But there are many other aspects being equally important, in particular roles should reflect the organizational structure, should be acceptable by human users, easy to update, and should consider business constraints. The papers highlight some basic features on which Engiweb Security “IDEAS Role Constructor” module is based.

The abstracts:

A Probabilistic Bound on the Basic Role Mining Problem and its Applications
In this paper we describe a new probabilistic approach to the role engineering process for RBAC. In particular, we address the issue of minimizing the number of roles, problem known in literature as the Basic Role Mining Problem (basicRMP). We leverage the equivalence of the above issue with the vertex coloring problem. Our main result is the proof that the minimum number of roles is sharply concentrated around its expected value. A further contribution is to show how this result can be applied as a stop condition when striving to find out an approximation for the basicRMP.
We also show that the proposal can be used to decide whether it is advisable to undertake the efforts to renew an RBAC state. Note that both these applications can result in a substantial saving of resources. A thorough analysis using advanced probabilistic tools supports our results.
Finally, further relevant research directions are also highlighted.

Mining Stable Roles in RBAC
In this paper we address the problem of generating a candidate role set for an RBAC configuration that enjoys the following two key features: it minimizes the administration cost; and, it is a stable candidate role-set.
To achieve these goals, we implement a three steps methodology: first, we associate a weight to roles; second, we identify and remove the user-permission assignments that can not belong to a role having a weight exceeding a given threshold; third, we restrict the problem of finding a candidate role-set for the given system configuration using only the user-permission assignments that have not been removed in step two (that is, user-permission assignments that belong to roles having a weight exceeding the given threshold). We formally show-proof of our results are rooted in graph theory-that this methodology achieves the intended goals.
Finally, we discuss practical applications of our approach to the role mining problem.

Authors: Alessandro Colantonio, Roberto Di Pietro, Alberto Ocello, Nino Verde.

If you are interested in receiving the full texts, please send me an e-mail: my surname at eng dot it.

Wednesday, December 3, 2008

Musings on Bruno Munari thoughts

Last Sunday I was walking downtown in the historical center of Rome, and as I was strolling along the Tiber river I came across the Ara Pacis Museum. These days the exhibit area inside Ara Pacis is hosting an exhibition on Bruno Munari.
The new museum, designed by the Richard Meier architect is quite charming: I like its pristine structure that is full of light, but what really touched me was the Bruno Munari exhibition.
In fact Munari’s works and his attitude of whimsy and sheer inventive imagination were actually venerated by me when I was a kid.

From the catalog:
“Munari’s life (1907-1998) and career spanned the 20th century, and he was among the most seminal exponents of Italian design and graphic design. Yet he never received the accolades and recognition on an international scale that he so richly deserved. What sets Munari apart from other designers is that he engaged in a quiet, playful revolution, inventing and designing with humorous and modest creativity, challenging all conventions and stereotypes intelligently but without flamboyance.”
But let me tell you why I’m speaking of Bruno Munari in this blog.

Walking along the exhibit set course, I noticed some of Munari’s sentences on the walls, and among them one in particular attracted some attention:

“Progresso รจ quando si semplifica, non quando si complica”
“Progress is when things get simpler, not more complicated”

I like to use quotes to mix things up: in this case Bruno Munari reminds me of the aggregation (and/or acquisition) processes currently taking place in the Identity Management space.
We, as all vendors, are supporting our customers move from automating infrastructure procedures (that is meta-directory services, basic identity administration and access management) to enabling business processes, towards the satisfaction of the new requirements for Governance, Risk and Compliance (GRC).
Thus most vendors started down that path of adding new features, and new modules; often with the shortcut of specialized company acquisitions.

And the result is. ......Yes, for sure we are allowed to check the coarse grain Role checkbox in RFP's, and if the prospect asks for a POC we can always mask the mess, ..... and in parallel: let’s pump cosmetic marketing campaigns.

So if the product isn’t built, since the beginning, around a data model that is able to natively manage all processes linked to identity, role life cycles and access governance, just two alternatives are available:
  • Rewriting from scratch the product around a coherent and complete data model;
  • Try immediately to trim the fat, hide the complexity and hope that the discrepancy that exists will definitely be decreased in the next releases and beyond…
What is happening in the present Enterprise Role management vendor acquisition fever is quite typical.

Is it possible to really integrate an Identity Management solution with an Advanced Role Management solution? And what are the risks associated with this two-headed architecture?

I will write more about this in the next post and try to explain our idea of integrated solution that is able to natively support all the needed features in a scenario, where Advanced Role Management capabilities together with strong Authorization Management is gaining momentum

Tuesday, November 25, 2008

SOA and IAM are growing together

As promised in my previous post I’m introducing a new feature that adds a lot of value to our IDEAS solution: the support of SOA-based integration platform for providing a direct connection to Resource Target systems. This is the starting point for a clear commitment to SOA support, which we hope will continue to grow.
Collaboration between SOA (Service-Oriented Architectures) and Identity Management is an important requirement for many customers that have SOA based applications, and are looking for an application-wide use of identity and authorization data.

What we have done was simply to optimize the synergies with our mother company: Engineering Ingegneria Informatica (EII).
Actually EII is a strategic member and co-founder of the international OW2 Consortium. Within this Consortium, EII is particularly active on the project Spagic that aims at enlarging the OW2 Consortium code-base to support the development of business applications according to the SOA (Service Oriented Architecture) paradigm.
"Spagic is a solution composed by a set of visual tools and back-end applications oriented towards planning, realization, deploy and monitoring of ESB infrastructures adherent to the SOA paradigm. By means of visual tools, Spagic can be easily adopted by different categories of users involved in integration projects, such as: analysts defining the integration processes, developers realising application services, users monitoring and managing the entire system."

Engiweb Security has built specific components of IDEAS integrating SPAGIC (that includes ServiceMIX), in order to be able to directly support a SOA-based integration platform.
The first output is the capability to access JDBC Resource Target directly via a SOAP adapter.
Using its native JMS interface, the IDEAS platform can now exchange events with SPAGIC and on other side targets are connected to the JDBC Communication Layer provided by the SPAGIC SOA/BPM Enterprise Integration Framework.
So a customer is able to centralize the administration of user identities and their associated access privileges to corporate resources using the central IDEAS module, and using the SOA Interface it allows the synchronization of Identity/roles data with external applications that manage such information in a JDBC environment.
As a matter of fact, in this scenario a consistent state of identity information in connected external systems is provided without the need of a “traditional” resource provisioning systems (e.g. Novell’s Identity Manager connectors).

Extending the Scenario
  1. We are working to integrate IDEAS with other SOA Platforms such as JBOSS-ESB and TIBCO.
  2. The integration of SOA Platforms will gather in pace and importance in this coming year with the result that events coming in and out from IDEAS will be processed by an orchestration of different services and data integration oriented services, allowing for complex Business Logic implementations and collaborative activities within several Web services.

Tuesday, November 4, 2008

A pragmatic approach to “Virtualization”

My company, Engiweb Security, is quite small, but I think, has many strengths and is well positioned to play a vital role in the role based identity management and the GRC markets.
One of the innovative aspects that, is worth sharing is our approach to “Virtualization”. Here we don’t want to take sides in the dispute between Meta-Directories versus Virtual Directories: they are both well respected technologies and, looking at our solution IDEAS, I view these technologies as complementary. As a matter of fact we have a hybrid approach.
Most Identity related information is consolidated in the IDEAS master repository (based on a RDBMS) using specific connectors to Target Resources. But there is also an interface to other repositories to provide the required attributes without any need to move information from the existing user repository, thus providing a combined view of all user data.

In other words a sort of “Virtual Directory” or "Identity Virtualization".

The combination of the Master Repository with its strong data model behind (able to manage identity information, policies, business roles, …) and the Virtual data aggregation, allows an external application to have all the needed information to act in a secure way.
For this purpose IDEAS is equipped with API JAVA, API .NET and Web Services which permit an external application to see the required data as one data source, and recover the user security context.
So, applications might require user data that is stored non only in the central IDEAS repositories, but also in scattered different repositories (DB, directories, ..).
This approach makes it possible to keep the central repository lean, no need to fatten it if an application needs some specific data (i.e. external attributes) that are not relevant for other applications.
Furthermore some of these external attributes could also support the internal rule engine processes, where some decisions have to be taken considering specific parameters.

In the next post I’ll introduce another element that, from my point of view, adds a lot of value to our IDEAS solution: the support of SOA-based integration platform for providing a new generation of “Target Resource” connectors.

Friday, September 19, 2008

Do I have an alter ego?

A few days ago I received an e-mail from Courion Corporation: “Register Today: Sept Webinars Now Posted”. … and reading the content, I jumped.


Yes, one of the webinar title was just like the name of this blog: “Roles in Action”.

Of course I will not claim ‘firstborn’ rights. Very often in marketing you can create a catchword using a simple buzzword generator. For example, within my company we recently named a webcast: “Role Management: unlock the complete value of Identity Management, take full control over Compliance”. Not very original, is it?

Anyway, I am looking forward to this webinar. I hope that Courion speaker, Chris Sullivan, will agree with my blog subtitle: “Roles can’t be built in a day”.