DocumentCode
593696
Title
A lattice interpretation of group-centric collaboration with expedient insiders
Author
Bijon, Khalid Zaman ; Ahmed, Toufik ; Sandhu, Ravi ; Krishnan, Ram
Author_Institution
Dept. of Comput. Sci., Univ. of Texas at San Antonio, San Antonio, TX, USA
fYear
2012
fDate
14-17 Oct. 2012
Firstpage
200
Lastpage
209
Abstract
For various reasons organizations need to collaborate with external consultants, e.g. domain specialists, on specific projects. Many security-oriented organizations deploy multi-level systems which enforce one directional information flow in a lattice of security labels. However, traditional lattice constructions are not suitable for accommodating external consultants, since such consultants are not “true insiders” but rather “expedient insiders” who should receive much more limited privileges than employees. An authorization model for group-centric collaboration with expedient insiders (GEI) has been recently proposed, wherein organizations create groups and replicate the organizational lattice with selected content for such collaborations [4]. Motivated by GEI, in this paper, we formulate a novel lattice construction wherein a new collaboration category is introduced for each new collaboration group, in a manner significantly different from the usual process of defining new security categories in a lattice. In particular, a collaboration category brings together only the required objects and users. We develop a formal model for lattices with collaborative compartments (LCC) comprising administrative and operational parts covering the life-cycle of such collaborations. We formally prove the equivalence of LCC and GEI, thereby precisely characterizing the information flow and security properties of GEI which heretofore had only been informally considered. This equivalence shows that GEI can be realized via LBAC with minimal operational disruptions.
Keywords
authorisation; groupware; collaboration category; collaboration group; collaborative compartment; directional information flow; formal model; group centric collaboration; lattice construction; lattice interpretation; multilevel system; organizational lattice; security label; security oriented organization; Security; Group Centric Collaboration; Information Sharing; Lattice Based Access Control;
fLanguage
English
Publisher
ieee
Conference_Titel
Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2012 8th International Conference on
Conference_Location
Pittsburgh, PA
Print_ISBN
978-1-4673-2740-4
Type
conf
Filename
6450908
Link To Document