DocumentCode
2909501
Title
A trust and reputation-based access control model for virtual organizations
Author
Arasteh, M. ; Amini, Milad ; Jalili, Rasool
Author_Institution
Dept. of Comput. Eng., Sharif Univ. of Technol., Tehran, Iran
fYear
2012
fDate
13-14 Sept. 2012
Firstpage
121
Lastpage
127
Abstract
Virtual organization (VO) is aimed to provide inter-organizational collaborations. Constructing a VO necessitates provision of security and access control requirements which cannot be satisfied using the traditional access control models. This is basically due to special features of VOs; such as temporality, unknown users, and diverse resources. In this paper, after expressing our assumption on a framework for VOs; the concept of organizational trust and reputation is used to establish an access control model for VOs. Each member of an organization inherits its organizational reputation. Resource providers announce the behavior of their interacting users to their organization manager. According to the received feedbacks, organization managers calculate the new amount of trust for each guest organization. Afterwards, the VO manager calculates organizations reputation by integrating trust values received from organizations. A selfish organization may use the other organization resources and not offer any resources to the requester organizations. To overcome this problem, we use single policy and authorization system for all members of the VO. By combining resource providers´ policies, a unique policy for each shared resource in the VO will be formed. In VOs there are various and heterogeneous entities, to address this challenge and preparing common perception we suggest using ontology in the virtual organization. The advantage and usefulness of the proposed method is compared with the conventional approaches.
Keywords
authorisation; ontologies (artificial intelligence); organisational aspects; resource allocation; trusted computing; virtual enterprises; VO manager; guest organization; heterogeneous entities; interorganizational collaborations; ontology; organization resource provider policies; organizational reputation-based access control model; organizational trust-based access control model; requester organizations; trust values; user interaction; virtual organization manager; Authorization; Object oriented modeling; Ontologies; Organizations; Peer to peer computing; Access Control; Organizational Reputation; Organizational Trust; Virtual Organization (VO);
fLanguage
English
Publisher
ieee
Conference_Titel
Information Security and Cryptology (ISCISC), 2012 9th International ISC Conference on
Conference_Location
Tabriz
Print_ISBN
978-1-4673-2387-1
Type
conf
DOI
10.1109/ISCISC.2012.6408204
Filename
6408204
Link To Document