• DocumentCode
    2027963
  • Title

    A secure, constraint-aware role-based access control interoperation framework

  • Author

    Baracaldo, Nathalie ; Masoumzadeh, Amirreza ; Joshi, James

  • Author_Institution
    Sch. of Inf. Sci., Univ. of Pittsburgh, Pittsburgh, PA, USA
  • fYear
    2011
  • fDate
    6-8 Sept. 2011
  • Firstpage
    200
  • Lastpage
    207
  • Abstract
    With the growing needs for and the benefits of sharing resources and information among different organizations, an interoperation framework that automatically integrates policies to facilitate such cross-domain sharing in a secure way is becoming increasingly important. To avoid security breaches, such policies must enforce the policy constraints of the individual domains. Such constraints may include temporal constraints that limit the times when the users can access the resources, and separation of duty (SoD) constraints. Existing interoperation solutions do not address such cross-domain temporal access control and SoDs requirements. In this paper, we propose a role-based framework to facilitate secure interoperation among multiple domains by ensuring the enforcement of temporal and SoD constraints of individual domains. To support interoperation, we do not modify the internal policies, as most of the current approaches do. We present experimental results to demonstrate our proposed framework is effective and easily realizable.
  • Keywords
    authorisation; SoD; constraint aware role based access control interoperation framework; interoperation framework; interoperation security; policy constraints; separation of duty; temporal constraints; Access control; Organizations; Radio frequency; Semantics; Time factors; Upper bound;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security (NSS), 2011 5th International Conference on
  • Conference_Location
    Milan
  • Print_ISBN
    978-1-4577-0458-1
  • Type

    conf

  • DOI
    10.1109/ICNSS.2011.6060001
  • Filename
    6060001