• DocumentCode
    2070650
  • Title

    A trust model for capability delegation in federated policy systems

  • Author

    Feeney, Kevin ; Foley, Simon N. ; Brennan, Rob

  • Author_Institution
    Intell. Syst. Lab., Trinity Coll., Dublin, Ireland
  • fYear
    2011
  • fDate
    26-28 Sept. 2011
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Federated policy systems are required to support the emergent complexity and organizational heterogeneity of modern Internet service delivery. This paper presents a distributed policy management approach which utilizes a flexible, tree-based capability authority model to partition and delegate federated capabilities or services. A trust management model and a delegation logic is defined which supports secure decentralized policy reasoning and addresses performance overheads due to distributed rule evaluation, threats from malformed or malicious federated principals and allows flexibility with respect to delegation chain reduction or capability authority re-partitioning. The system is evaluated through a security analysis and a prototype implementation of a federated policy engineering framework based on this logic is described. This framework is based on public key certificates and an extension to the Keynote Trust Management language. It provides practical management services such as key discovery and certificate revocation in addition to the core capability delegation function.
  • Keywords
    Internet; distributed processing; public key cryptography; Internet service delivery; capability authority re-partitioning; core capability delegation function; delegation chain reduction; delegation logic; distributed policy management; distributed rule evaluation; emergent complexity; federated policy engineering framework; federated policy systems; keynote trust management language; malicious federated principals; organizational heterogeneity; public key certificates; security analysis; tree-based capability authority model; trust management model; Authorization; Information services; Internet; Public key; Semantics; Web and internet services; Federated Management; Policy Based Management; Security; Service Management; Trust Management;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Risk and Security of Internet and Systems (CRiSIS), 2011 6th International Conference on
  • Conference_Location
    Timisoara
  • Print_ISBN
    978-1-4577-1890-8
  • Electronic_ISBN
    978-1-4577-1889-2
  • Type

    conf

  • DOI
    10.1109/CRiSIS.2011.6061828
  • Filename
    6061828