DocumentCode :
2953088
Title :
Identity Delegation in Policy Based Systems
Author :
Gupta, Rajeev ; Roy, Shourya ; Bhide, Manish
Author_Institution :
IBM, New Delhi
fYear :
2007
fDate :
13-15 June 2007
Firstpage :
229
Lastpage :
240
Abstract :
Policy based systems have received considerable attention in the recent past from academia as well as the industry. Research on policy based systems encompasses a gamut of areas such as: models and languages for policy based systems, policy standards, domain specific implementations, policy tools etc. However an important issue, which did not receive much attention from researchers, is that of access control for policy execution. In this paper we present the concept of "identity delegation" which involves finding the \´correct\´ users/ identities, to whom task of policy execution can be delegated. Policies are generally defined by high level business executives (policy authors) and are implemented by policy enforcers who have sufficient access rights on the underlying systems. Given the increasing complexity of enterprise systems, we show in this paper that finding the right policy enforcers for a policy can be a fairly non-trivial task. We address this important problem by proposing a unique concept of \´implicit identity delegation\´, whereby an autonomic system automatically figures out the correct policy enforcers and implicitly delegates the task of policy execution. We present the Implicit Identity Delegation architecture which boasts of an efficient technique for performing implicit identity delegation and uses a plugin based architecture ensuring its applicability and use in diverse domains.
Keywords :
authorisation; access control; enterprise systems; implicit identity delegation architecture; policy based systems; policy execution; policy standards; Access control; Databases; Decision making; Electrical equipment industry; Gold; High level languages; Natural languages; Permission; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Policies for Distributed Systems and Networks, 2007. POLICY '07. Eighth IEEE International Workshop on
Conference_Location :
Bologna
Print_ISBN :
0-7695-2767-1
Type :
conf
DOI :
10.1109/POLICY.2007.26
Filename :
4262592
Link To Document :
بازگشت