Projects
Identity and Access Management for Intelligent Agents: Interdomain Trust and Risks
Investigate trust, authorization and access revocation for AI agents operating across administrative domains.
About the project
The rise of independent AI agents introduces a fundamental new class of actors in distributed systems. These agents combine the computational speed and scalability of services with the spontaneity, autonomy, and discovery capabilities of humans. This project contributes to the field of Identity and Access Management (IAM) and aims to evaluate existing tools for IAM of people and workloads and propose practices, adaptations, and extensions that enable the secure management of AI agents. Current identity and authorization systems are useful for agent systems in a single administrative domain, but this management is insufficient for systems spanning multiple domains. This project will investigate how to withstand trust models that span multiple administrative domains and how to reconcile different authentication and authorization standards. Furthermore, the context of AI agency is comprehensive and will require the sharing of new risk signals that indicate the need to revoke agent identities or authorizations.
GT-BAITA
Connect academic institutions and their digital services through an interoperable identity federation, with service discovery and decentralized trust.
Objectives and approach
The GT-BAITA (Grupo de Trabalho - Barramento de Interoperabilidade Acadêmica) project aims to design and implement a dynamic interoperability ecosystem connecting Identity Providers (IdPs) and Service Providers (SPs) within a federated consortium, based on the widely adopted identity and authorization standards OAuth 2.0 and OpenID Connect, and leveraging the emerging OpenID Federation specification to enable scalable, secure, and decentralized trust establishment. Through the adoption of an OpenID Federation-based architecture, GT-BAITA seeks to (i) enable institutions within the Brazilian research and development ecosystem to share digital services in a reliable, interoperable, and autonomous manner; (ii) support the development of an automated SP discovery mechanism that allows end users to transparently identify and access services offered by federation members, (iii) provide an intelligent Where Are You From (WAYF) service capable of ensuring both syntactic and semantic interoperability between IdPs and SPs while dynamically satisfying SP requirements such as Multi-Factor Authentication (MFA), and (iv) lay the foundations for the future integration of Verifiable Credentials (VCs), enabling attribute-based interactions and higher levels of privacy within the federation.
ADES
Simplify document signing with electronic identity and one-time certificates, without requiring users to manage digital certificates.
About the project
The ADvanced Electronic Signature (ADES) project simplifies the digital signing process by removing the need for users to deal with the technical aspects of digital certificates. Traditional methods often require managing a smartcard, a certificate file with a private key, a USB token, or a cloud-based certificate provider—solutions that can be intimidating and overly complex for most users. ADES replaces this with a more user-friendly approach: it uses familiar identity providers like Google, Meta, or LinkedIn to authenticate the user. Behind the scenes, a One-Time Certificate (OTC) is generated for each document. Issued by a certification authority within a public-key infrastructure, this OTC is valid for 100 years. As a result, users gain the long-term benefits of digital signatures without the burden of maintaining certificates or renewing timestamps.
Applications and results
Try our online demo, already trusted by millions every day through partnerships with Brazil's Civil Registry and the National Education and Research Network (RNP), as well as Mozambique's government and general public.
- Redefining Digital Web Signature Secrecy: A Client-Side Model for Enhanced Security and Compliance;
- Exploring Digital Signatures Secrecy in Web-Platform: Client-Side Cryptographic Operations;
- Menos Certificação Digital e Mais Identidade Eletrônica: ICPEdu e CAFe em um Assinador Digital Inclusivo;
- Simplifying Electronic Document Digital Signatures;
- Processos de verificação e assinatura digital de documentos eletrônicos baseado em identidade eletrônica, certificado digital de uso único e blockchain.
Electronic Identity and PKI of Mozambique
Support a national electronic identity and public-key infrastructure, broadening access to digital signatures in Mozambique.
About the project
This project aims to implement an electronic identity and Public Key Infrastructure (PKI) platform in Mozambique, integrating ADES to enable digital signatures in an inclusive and broad manner. The goal is to enable the entire population — even those using devices that are unable to render PDFs — to sign documents reliably, including via SMS.
With a focus on nationwide adoption, the initiative strengthens the security and legal validity of electronic signatures, fostering trust in public and private services. In addition, alignment with international standards ensures that Mozambique can expand the interoperability of its electronic identities and actively participate in the global digital ecosystem.
Applications and results
Checkout Mozambique's national PKI, which we supported INTIC in building. It underpins the country's publicly available digital signature platform, used daily to sign the Official Journal and a wide range of other documents.
IdRC
Bring Civil Registry identity into the digital environment to help citizens securely access registry services.
About the project
The Electronic Identity of the Civil Registry (IdRC) - seeks to offer a practical and secure way to expand access to the fundamental identity of Brazilians in the digital environment. Based on data registered in the registry offices of natural persons, IdRC enables citizens to use a reliable electronic identity to access digital services, without replacing existing physical documents.
With a focus on integration and accessibility, IdRC connects civil registries to a modern platform, promotes interoperability with national systems and aligns with the guidelines of eIDAS, the European model for electronic identification. This relationship ensures that IdRC is prepared to meet global digital identity standards, strengthening Brazil on the international stage.
Applications and results
Already in production, supporting nearly 14 million Brazilians in securely accessing notary services nationwide.
- Identificaçao Eletrônica do Registro Civil do Brasil;
- Bridging the Gap: Managing Dual Assurance Levels in OpenID Connect;
- Enhancing Keycloak: Implementing OpenID Connect for Identity Assurance;
- Bringing Semantics to Authentication: An OpenID Connect Extension;
- Visão de Futuro: o Registro Civil do Brasil como Emissor de Credenciais Verificáveis.