• DocumentCode
    1843692
  • Title

    Enforcing Separation of Duty in Ad Hoc Collaboration

  • Author

    Deng, Lingli ; He, Yeping ; Xu, Ziyao

  • Author_Institution
    Inst. of Software, Chinese Acad. of Sci., Beijing
  • fYear
    2008
  • fDate
    18-21 Nov. 2008
  • Firstpage
    1545
  • Lastpage
    1552
  • Abstract
    By collaboration, domains share resources effectively. To maintain security properties of individual domains during collaboration is a key issue. When domains employing heterogeneous RBAC policies collaborate by crossdomain role-role mappings, their local SMER constraints may be violated. However, the secure interoperation studied so far does not deal with this threat. We presents the requirement for constraint secure interoperation, prohibiting implicit authorizations that break constraints of other member domain. We propose a framework for crossdomain constraint enforcement in dynamic mediator-free ad hoc collaboration. By introducing crossdomain migration of MD-SMERs, the framework ensures the global security in terms of SMERs from individual domains. Specifically, we introduce a bitmap-based history-recording mechanism for collaborating domains to analyze the interplay among innerdomain role hierarchies, crossdomain role-role mappings, and SMER constraints. Algorithms of a fully distributed implementation for the framework and its security proofs are given.
  • Keywords
    ad hoc networks; authorisation; groupware; telecommunication security; RBAC policy; bitmap-based history-recording mechanism; constraint secure interoperation; crossdomain constraint enforcement; crossdomain role-role mappings; dynamic mediator-free ad hoc collaboration; Access control; Authorization; Collaborative software; Data security; Helium; IP networks; Information security; International collaboration; Peer to peer computing; Resource management; Secure collaboration; role-based access control; separation of duty; statically mutually exclusive roles;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Young Computer Scientists, 2008. ICYCS 2008. The 9th International Conference for
  • Conference_Location
    Hunan
  • Print_ISBN
    978-0-7695-3398-8
  • Electronic_ISBN
    978-0-7695-3398-8
  • Type

    conf

  • DOI
    10.1109/ICYCS.2008.131
  • Filename
    4709203