Reference no: EM134020808
Assignment:
Identification & Authentication (IA) for sensitive location access :
The Parliament of Ruritania wishes to include more automation in the way it handles access to its new Parliamentary buildings around the country. In phase 1 of the project they wish to introduce a suitable access control system to permit the following categories of users to have access to the buildings. This new system will use automated gates in place of the existing pool of security guards as much as possible.
1) MPs, civil servants and other relevant employees.
2) Invited visitors (including journalists, lobbyists, and consultants).
Ruritania does not have a particularly robust or reliable Internet infrastructure and is highly reliant on mobile phone networks for most communications. The country has also recently been experiencing regular, but unpredictable, power cuts due to a border dispute with its main energy supplier.
You have been asked to advise on identification and authentication features required to ensure that the access control system can rely on the IA system. The IA system must continue to function at all times in spite of the aforementioned difficulties (unreliable Internet, reliance on mobile phone networks, and power cuts). You can assume that the access control system provides a suitable interface to any IA system, and that different levels of access authorisation are already implementable by the access control system itself. You should, however, give an indication of critical points where your IA system may need to be deployed to ensure that only those authorised to access particular areas actually have access - i.e., how your system can help to prevent unauthorised users from gaining access to rooms to which they should not have access. In particular, you are asked to perform three tasks (i, ii, and iii), given below.
Throughout, you should seek to provide justification for any choices you make. You should quote from or refer to the literature to provide evidence of costs and capabilities of particular approaches. Costs should not be restricted solely to equipment costs. You must justify choices for the system in context. This applies to your choice of initial criteria, and to the assessment of any proposed system. Thus any system architecture and technologies deployed should be reasonable choices based on plausible assessments of risk. (Your system must give value for money.)
Question:
i) Cost effectiveness is the first important criterion. Given the context, identify the four most important further criteria that you believe a suitable IA system must satisfy.
ii). Provide an IA system design and assess it against the five criteria identified in (i). (Your system may use as many IA mechanisms, in isolation or in combination, as you consider appropriate, but you must justify why each one is used).
iii) Provide an outline of how your system, specified in (ii), could be adapted to cope with a requirement to grant some level of access to constituents and tourists who wish to visit the Parliament building (i.e. occasional/irregular visitors who need not give any notice of their intent to attend).