A Privilege Management Scheme for Mobile Agent Systems
Wayne Jansen · Electronic Notes in Theoretical Computer Science · 2002
Controlled access to and limited consumption of resources,• Audit by both agents and platforms,• Authenticated and protected communications,• Signed code, andAgent systems typically incorporate such countermeasures into their design, where internal data structures reflect if, how, and when a security mechanism is applied.These data structures typically contain authorization information or privileges regarding an agent's capabilities on distributed systems, and conceptually serve as an internal passport for the agent.While these structures are often very similar semantically, they differ greatly in their implementation, depending largely on the mechanisms used to protect their contents.In reviewing a number of agent systems, we noted several shortcomings from using internal data structures to convey policy rules.• Among applications, the number of policy-setting principals and the trust relationships that are needed can vary considerably.However, within an agent system those representations are typically fixed and unchangeable.This dichotomy forces developers of agent-based applications to conform to the imposed scheme, which may or may not match well the intended security policy of their application.• Policy expression varies among agent systems in terms of granularity, language, and resource entities, and is often difficult for an application developer to modify or extend.When combined with the previous shortcoming, the overall result is to constrain a developer into a rigid framework that may require an elaborate work-around to express the intended policy or, at worst, may be completely inadequate for the needs of the application.• The means of protecting policy, once expressed and residing in an internal data structure, also varies among agent systems, particularly regarding strength of protection.Each agent system must be closely reviewed to decide whether the expressed policy is satisfactorily protected for the risk environment of the application.• Because the internal policy-related data structures, trust relationships, policy expression, and strength of policy protection as a whole differ widely among agents developed for different agent systems, the opportunity for interoperability of agent systems is severely limited.