DocumentCode
2027963
Title
A secure, constraint-aware role-based access control interoperation framework
Author
Baracaldo, Nathalie ; Masoumzadeh, Amirreza ; Joshi, James
Author_Institution
Sch. of Inf. Sci., Univ. of Pittsburgh, Pittsburgh, PA, USA
fYear
2011
fDate
6-8 Sept. 2011
Firstpage
200
Lastpage
207
Abstract
With the growing needs for and the benefits of sharing resources and information among different organizations, an interoperation framework that automatically integrates policies to facilitate such cross-domain sharing in a secure way is becoming increasingly important. To avoid security breaches, such policies must enforce the policy constraints of the individual domains. Such constraints may include temporal constraints that limit the times when the users can access the resources, and separation of duty (SoD) constraints. Existing interoperation solutions do not address such cross-domain temporal access control and SoDs requirements. In this paper, we propose a role-based framework to facilitate secure interoperation among multiple domains by ensuring the enforcement of temporal and SoD constraints of individual domains. To support interoperation, we do not modify the internal policies, as most of the current approaches do. We present experimental results to demonstrate our proposed framework is effective and easily realizable.
Keywords
authorisation; SoD; constraint aware role based access control interoperation framework; interoperation framework; interoperation security; policy constraints; separation of duty; temporal constraints; Access control; Organizations; Radio frequency; Semantics; Time factors; Upper bound;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and System Security (NSS), 2011 5th International Conference on
Conference_Location
Milan
Print_ISBN
978-1-4577-0458-1
Type
conf
DOI
10.1109/ICNSS.2011.6060001
Filename
6060001
Link To Document