• DocumentCode
    3150861
  • Title

    Role-based integrated access control and data provenance for SOA based net-centric systems

  • Author

    She, Wei ; Yen, I-Ling ; Bastani, Farokh ; Tran, Bao ; Thuraisingham, Bhavani

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Texas at Dallas, Dallas, TX, USA
  • fYear
    2011
  • fDate
    12-14 Dec. 2011
  • Firstpage
    225
  • Lastpage
    234
  • Abstract
    Service-oriented architecture (SOA) has been widely adopted in the development of many net-centric application systems. In SOA, services potentially from different domains are composed together to accomplish critical tasks. In these systems, security and trustworthiness are the major concerns that have not been well addressed. Many access control models have been developed to ensure proper accesses to critical resources from local as well as external domains. Also, many data provenance schemes have been proposed in recent years to support data quality assessment and enhancement, data reproduction, etc. However, none of the existing mechanisms consider both access control and data provenance in a unified model. In this paper, we propose an integrated role-based access control and data provenance model to secure the cross-domain interactions. We develop a role-based data provenance scheme which tracks the roles of the data originators and contributors and uses this information to help evaluate data trustworthiness. We also make use of the data provenance information and the derived data quality attributes to assist with role-based access control. In this integrated model, the secure usage of a data resource must also consider the quality and trustworthiness of the data. To realize this concept, we develop an extended access control model in which access permissions are specified with constraints over the provenance attributes. Also, to assure confidentiality, we record the access constraints from the data originators and contributors to help decide how the data should be further disseminated.
  • Keywords
    authorisation; service-oriented architecture; SOA based net-centric systems; data provenance model; data trustworthiness; role-based integrated access control; service-oriented architecture; Access control; Computational modeling; Data models; Organizations; Reliability; Service oriented architecture; Role-based model; access control; data provenance; data quality; trustworthiness;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Service Oriented System Engineering (SOSE), 2011 IEEE 6th International Symposium on
  • Conference_Location
    Irvine, CA
  • Print_ISBN
    978-1-4673-0411-5
  • Electronic_ISBN
    978-1-4673-0410-8
  • Type

    conf

  • DOI
    10.1109/SOSE.2011.6139111
  • Filename
    6139111