Title :
Towards General Access Control Management for Middleware Security
Author :
Yin, Gang ; Shi, Dianxi ; Sui, Pinbo ; Wang, Huaimin
Author_Institution :
Sch. of Comput., Nat. Univ. of Defense Technol., Changsha, China
Abstract :
Middleware security is usually regarded as a wrapper of underlying security mechanisms rather than a infrastructure for enforcement and management of access control policies. We argue that there is a need for more generalized security mechanisms at middleware layer to enforce multiple access control policies. We introduce StarACM, a novel policy-oriented security architecture at middleware layer, which is distinguished from existing middleware security infrastructures mainly in three aspects: (1) StarACM can be used to enforce access control policies with finer granularity and different kinds of constraints. (2) StarACM provides a more general policy management infrastructure to keep the privacy, consistency and availability of access control policies. (3) StarACM provides means to clearly separate authorization logic from applications, which will be enforced at middleware layer. StarACM is built upon a CORBA middleware and supports multiple access control policies while preserving the middleware designing characteristics.
Keywords :
authorisation; distributed object management; middleware; CORBA middleware; StarACM; StarBus-based access control management; authorization logic; constraints; general access control management; granularity; middleware security infrastructures; multiple access control policies; policy management infrastructure; policy-oriented security architecture; Access control; Computer architecture; Computer security; Conference management; Containers; Data security; Information security; Logic; Middleware; National security; Access Control; Middleware; Policy; Security;
Conference_Titel :
INC, IMS and IDC, 2009. NCM '09. Fifth International Joint Conference on
Conference_Location :
Seoul
Print_ISBN :
978-1-4244-5209-5
Electronic_ISBN :
978-0-7695-3769-6
DOI :
10.1109/NCM.2009.273