• DocumentCode
    410112
  • Title

    Implement role based access control with attribute certificates

  • Author

    Wei Zhou ; Meinel, C.

  • Author_Institution
    University of Trier
  • Volume
    1
  • fYear
    2004
  • fDate
    9-11 Feb. 2004
  • Firstpage
    536
  • Lastpage
    540
  • Abstract
    Nowadays more and more activities are performed over the Internet. But as more people are involved in the transaction circle, security and authorization control becomes one of the biggest concerns. Hence, We are motivated by the need 10 manage and to enforce a strong authorization mechanism in large-scale web-environment. Role based access control (RBAC) provides some flexibility to security management. Public key infrastructure (PKI) can provide a strong authentication. Privilege management infrastructure (PMI) as a new technology can provide strong authorization. In order to satisfy mentioned security requirements, we have established a role based access control infrastructure and developed a prototype that uses X.509 public key certificates (PKCs) and attribute certificates (ACs). Access control is performed by access control policies that are written in XML. Policies and roles are stored in ACs. PKCs and AO are all stored in LDAP servers. A new solution for policy management is described. The main components of the prototype are administration tool and access control engine. The access control engine provides a service that mediates the data between the users and the resources, which is also responsible for authentication and authorization. The administration tool can create key pairs, PKCs and ACs, manage users´ information, and so on.
  • Keywords
    Access control; Authentication; Authorization; Computer science; Internet; Permission; Prototypes; Public key; Security; Technology management; Role based access control; X.509; XML; amibute certificates; authentication; authorization; privilegemanagement infrastructure; public key certificates; public keyinfrastructure;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Communication Technology, 2004. The 6th International Conference on
  • Conference_Location
    Phoenix Park, Korea
  • Print_ISBN
    89-5519-119-7
  • Type

    conf

  • DOI
    10.1109/ICACT.2004.1292928
  • Filename
    1292928