• DocumentCode
    1891687
  • Title

    Domain-Based Access Control for Collaborative E- Commerce System

  • Author

    Zhao, Hui ; Fang, Zhiyi ; Shi, Lijun ; Zhao, Dan

  • Author_Institution
    Jilin Univ., Changchun
  • fYear
    2007
  • fDate
    26-27 July 2007
  • Firstpage
    162
  • Lastpage
    167
  • Abstract
    The collaborative e-commerce systems are widely used between the enterprise and enterprise to strengthen cooperating ability of enterprises in dynamic business environment. Since the collaborative e-commerce systems are often shared by different enterprises, powerful access control is needed to allow different access rights to different records of the same table. Traditional access control models that define a permission as the right of a user/role to perform a specific operation on a specific object cannot handle the enormous amount of objects and user/roles. In this paper we propose an enhancement to role-based access control by introducing the domains that flexibly partition access control scope and exceed the limit of the organization frame. And, the domains fix the restrictions that can be added to the traditional concept of permissions in order to keep the number of permissions small. Furthermore, we present an implementation of our access control model at the application programming level. Although access control is performed for every single database access, our solution separates access control from the application logic by using component-based programming. With this, access control can be integrated into a four-tier information system without compiling the application programs.
  • Keywords
    authorisation; electronic commerce; groupware; object-oriented programming; relational databases; collaborative e-commerce system; component-based programming; database access; database table records; domain-based access control; dynamic business environment; four-tier information system; role-based access control; Access control; Authorization; Business; Collaboration; Collaborative work; Electronic commerce; Logic programming; Permission; Power system modeling; Resource management; Access Control; Domain; Integration; Restriction; Transaction;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Pervasive Computing and Applications, 2007. ICPCA 2007. 2nd International Conference on
  • Conference_Location
    Birmingham
  • Print_ISBN
    978-1-4244-0971-6
  • Electronic_ISBN
    978-1-4244-0971-6
  • Type

    conf

  • DOI
    10.1109/ICPCA.2007.4365432
  • Filename
    4365432