• DocumentCode
    2909501
  • Title

    A trust and reputation-based access control model for virtual organizations

  • Author

    Arasteh, M. ; Amini, Milad ; Jalili, Rasool

  • Author_Institution
    Dept. of Comput. Eng., Sharif Univ. of Technol., Tehran, Iran
  • fYear
    2012
  • fDate
    13-14 Sept. 2012
  • Firstpage
    121
  • Lastpage
    127
  • Abstract
    Virtual organization (VO) is aimed to provide inter-organizational collaborations. Constructing a VO necessitates provision of security and access control requirements which cannot be satisfied using the traditional access control models. This is basically due to special features of VOs; such as temporality, unknown users, and diverse resources. In this paper, after expressing our assumption on a framework for VOs; the concept of organizational trust and reputation is used to establish an access control model for VOs. Each member of an organization inherits its organizational reputation. Resource providers announce the behavior of their interacting users to their organization manager. According to the received feedbacks, organization managers calculate the new amount of trust for each guest organization. Afterwards, the VO manager calculates organizations reputation by integrating trust values received from organizations. A selfish organization may use the other organization resources and not offer any resources to the requester organizations. To overcome this problem, we use single policy and authorization system for all members of the VO. By combining resource providers´ policies, a unique policy for each shared resource in the VO will be formed. In VOs there are various and heterogeneous entities, to address this challenge and preparing common perception we suggest using ontology in the virtual organization. The advantage and usefulness of the proposed method is compared with the conventional approaches.
  • Keywords
    authorisation; ontologies (artificial intelligence); organisational aspects; resource allocation; trusted computing; virtual enterprises; VO manager; guest organization; heterogeneous entities; interorganizational collaborations; ontology; organization resource provider policies; organizational reputation-based access control model; organizational trust-based access control model; requester organizations; trust values; user interaction; virtual organization manager; Authorization; Object oriented modeling; Ontologies; Organizations; Peer to peer computing; Access Control; Organizational Reputation; Organizational Trust; Virtual Organization (VO);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security and Cryptology (ISCISC), 2012 9th International ISC Conference on
  • Conference_Location
    Tabriz
  • Print_ISBN
    978-1-4673-2387-1
  • Type

    conf

  • DOI
    10.1109/ISCISC.2012.6408204
  • Filename
    6408204