DocumentCode
1891687
Title
Domain-Based Access Control for Collaborative E- Commerce System
Author
Zhao, Hui ; Fang, Zhiyi ; Shi, Lijun ; Zhao, Dan
Author_Institution
Jilin Univ., Changchun
fYear
2007
fDate
26-27 July 2007
Firstpage
162
Lastpage
167
Abstract
The collaborative e-commerce systems are widely used between the enterprise and enterprise to strengthen cooperating ability of enterprises in dynamic business environment. Since the collaborative e-commerce systems are often shared by different enterprises, powerful access control is needed to allow different access rights to different records of the same table. Traditional access control models that define a permission as the right of a user/role to perform a specific operation on a specific object cannot handle the enormous amount of objects and user/roles. In this paper we propose an enhancement to role-based access control by introducing the domains that flexibly partition access control scope and exceed the limit of the organization frame. And, the domains fix the restrictions that can be added to the traditional concept of permissions in order to keep the number of permissions small. Furthermore, we present an implementation of our access control model at the application programming level. Although access control is performed for every single database access, our solution separates access control from the application logic by using component-based programming. With this, access control can be integrated into a four-tier information system without compiling the application programs.
Keywords
authorisation; electronic commerce; groupware; object-oriented programming; relational databases; collaborative e-commerce system; component-based programming; database access; database table records; domain-based access control; dynamic business environment; four-tier information system; role-based access control; Access control; Authorization; Business; Collaboration; Collaborative work; Electronic commerce; Logic programming; Permission; Power system modeling; Resource management; Access Control; Domain; Integration; Restriction; Transaction;
fLanguage
English
Publisher
ieee
Conference_Titel
Pervasive Computing and Applications, 2007. ICPCA 2007. 2nd International Conference on
Conference_Location
Birmingham
Print_ISBN
978-1-4244-0971-6
Electronic_ISBN
978-1-4244-0971-6
Type
conf
DOI
10.1109/ICPCA.2007.4365432
Filename
4365432
Link To Document