Title :
A lattice interpretation of group-centric collaboration with expedient insiders
Author :
Bijon, Khalid Zaman ; Ahmed, Toufik ; Sandhu, Ravi ; Krishnan, Ram
Author_Institution :
Dept. of Comput. Sci., Univ. of Texas at San Antonio, San Antonio, TX, USA
Abstract :
For various reasons organizations need to collaborate with external consultants, e.g. domain specialists, on specific projects. Many security-oriented organizations deploy multi-level systems which enforce one directional information flow in a lattice of security labels. However, traditional lattice constructions are not suitable for accommodating external consultants, since such consultants are not “true insiders” but rather “expedient insiders” who should receive much more limited privileges than employees. An authorization model for group-centric collaboration with expedient insiders (GEI) has been recently proposed, wherein organizations create groups and replicate the organizational lattice with selected content for such collaborations [4]. Motivated by GEI, in this paper, we formulate a novel lattice construction wherein a new collaboration category is introduced for each new collaboration group, in a manner significantly different from the usual process of defining new security categories in a lattice. In particular, a collaboration category brings together only the required objects and users. We develop a formal model for lattices with collaborative compartments (LCC) comprising administrative and operational parts covering the life-cycle of such collaborations. We formally prove the equivalence of LCC and GEI, thereby precisely characterizing the information flow and security properties of GEI which heretofore had only been informally considered. This equivalence shows that GEI can be realized via LBAC with minimal operational disruptions.
Keywords :
authorisation; groupware; collaboration category; collaboration group; collaborative compartment; directional information flow; formal model; group centric collaboration; lattice construction; lattice interpretation; multilevel system; organizational lattice; security label; security oriented organization; Security; Group Centric Collaboration; Information Sharing; Lattice Based Access Control;
Conference_Titel :
Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2012 8th International Conference on
Conference_Location :
Pittsburgh, PA
Print_ISBN :
978-1-4673-2740-4