Managing authorization in government management systems: the experience of SIARE-Artefactos
DOI:
https://doi.org/10.19153/cleiej.29.3.3Keywords:
Microservices, Public Sector, Authorization, DevOps, OAuth 2.0Abstract
Public administration software systems are increasingly adopting microservices architectures to achieve scalability, flexibility, and resilience. However, the complexity of distributed systems poses challenges to access authorization management. This study presents the SIARE-Artefactos solution, which is designed to automate the registration and authorization of resources within Paraguay’s Integrated State Resource Management System (SIARE). SIARE-Artefactos leverages OAuth 2.0 and Spring Boot Starter to ensure secure and efficient authorization processes. SIARE-Artefactos leverages OAuth 2.0 and Spring Boot Starter to ensure secure and efficient authorization processes. SIARE-Artefactos has been implemented and used by public employees in Paraguay, enabling validation with real users. For the validation we adopted a mixed-methods, combining quantitative with qualitative sources, and a longitudinal observational design. The convergence of evidence allowed us to correlate the objective reduction in deployment times (from minutes to seconds) with the subjective perception of 'system predictability' reported by the DevOps team. Validation of the proposal demonstrates the solution's replicability to other cases with similar challenges and resources, as well as its ability to significantly improve system reliability and reduce configuration time by 74%. This highlights its potential to transform large-scale public administration systems using modern DevOps practices and agile methodologies.
References
M. Fowler and J. Lewis, "Microservices: a definition of this new architectural term," 2014. [Online]. Available: https://martinfowler.com/articles/microservices.html
F. Zhang, G. Sun, B. Zheng, and L. Dong, "Design and implementation of energy management system based on Spring Boot framework," Information, vol. 12, no. 11, p. 457, 2021. [Online]. Available: http://dx.doi.org/10.3390/info12110457
A. Granda Rivera, "Distributed authorization for microservices-based applications," Master's thesis, Universitat Oberta de Catalunya, Barcelona, Spain, 2020. [Online]. Available:
http://openaccess.uoc.edu/webapps/o2/handle/10609/118346
D. Hardt, Ed., "The OAuth 2.0 Authorization Framework," IETF RFC 6749, Oct. 2012. [Online]. Available: http://dx.doi.org/10.17487/RFC6749
Gartner, "API Management: An Essential Component for Digital Business Platforms," 2019. [Online]. Available: https://www.gartner.com/
C. Gardner, D. Beaton, and K. Hartig, "The Forrester Wave: API Management Solutions, Q3 2022," Forrester Research, 2022. [Online]. Available: https://www.forrester.com/
M. B. Guayuan et al., "Automatic deployment of microservices in API manager," in Proc. 18th Iberian Conf. on Information Systems and Technologies (CISTI), Aveiro, Portugal, Jun. 2023. [Online]. Available: http://dx.doi.org/10.23919/CISTI58278.2023.10211516
R. Palau Heikel, M. González, and L. Cernuzzi, "SIARE-Artefactos: Automatización de la gestión de autorizaciones para microservicios en sistemas de gestión gubernamental," in Proc. 51st Latin American Informatics Conf. (CLEI), Valparaíso, Chile, 2025.
R. Palau Heikel, M. González, and L. Cernuzzi, "Gestión de autorización de acceso a microservicios en sistemas de gestión pública: una propuesta de automatización," in Proc. Ibero-American Conf. on Software Engineering (CIbSE 2025), Ciudad Real, Spain, May 2025, pp. 390-391. [Online]. Available: http://dx.doi.org/10.5753/cibse.2025.35335
R. Valecha, M. Kashyap, S. Rajeev, R. Rao, and S. Upadhyaya, "An activity theory approach to specification of access control policies in transitive health workflows," in International Conference on Information Systems, 2014.
A. Nehme and P. Jesus, "Fine-grained access control for microservices," in Proc. 34th ACM/SIGAPP Symp. on Applied Computing (SAC), Limassol, Cyprus, 2019, pp. 137-144.
R. Ahuja and S. K. Mohanty, "A scalable attribute-based access control scheme with flexible delegation cumsharing of access privileges for cloud storage," IEEE Trans. Cloud Comput., vol. 8, no. 1, pp. 32-44, Jan.-Mar. 2020. [Online]. Available: http://dx.doi.org/10.1109/TCC.2017.2751471
B. Burns, Designing Distributed Systems: Patterns and Paradigms for Scalable, Reliable Services. Sebastopol, CA, USA: O'Reilly Media, 2018. [Online]. Available:
https://www.oreilly.com/library/view/designing-distributed-systems/9781491983638/
N. Alshuqayran, N. Ali, and R. Evans, "A systematic mapping study in microservice architecture," in Proc. 2016 IEEE 9th Int. Conf. on Service-Oriented Computing and Applications (SOCA), Macau, China, Nov. 2016, pp.
-51. [Online]. Available: http://dx.doi.org/10.1109/SOCA.2016.15
R. F. Palau Heikel, M. B. Guayuan, M. L. Cremona, H. Nemeth, and J. C. Mello-Román, "Development of Applications Based on Microservices - Case Study of Ministry of Economy and Finance of Paraguay," in Proc. 50th Latin American Computer Conf. (CLEI), Buenos Aires, Argentina, 2024.
P. Runeson and M. Höst, "Guidelines for conducting and reporting case study research in software engineering," Empir. Softw. Eng., vol. 14, no. 2, pp. 131-164, 2009. [Online]. Available:
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Rafael Palau Heikel, Magalí González, Luca Cernuzzi

This work is licensed under a Creative Commons Attribution 4.0 International License.
CLEIej is supported by its home institution, CLEI, and by the contribution of the Latin American and international researchers community, and it does not apply any author charges whatsoever for submitting and publishing. Since its creation in 1998, all contents are made publicly accesibly. The current license being applied is a (CC)-BY license (effective October 2015; between 2011 and 2015 a (CC)-BY-NC license was used).