DocumentCode :
3263778
Title :
Intranet Security using Attribute Certificates under the Privilege Management Infrastructure
Author :
Tsai, Pi-Ju ; Tsai, Dwen-Ren ; Tai, Wen-Pin
Author_Institution :
M-Power Information Inc., Taipei, Taiwan.
fYear :
2005
fDate :
11-14 Oct. 2005
Firstpage :
1
Lastpage :
4
Abstract :
In the computerized organizations, the public key infrastructure (PKI) certifications enforce authentication services providing stronger security. The PKI provides a framework to verify the identity of each entity in a given domain. The PKI framework includes mechanisms of requesting, issuing, signing, and validating public-key certificates. The privilege management infrastructure (PMI) framework determines whether the entity is authorized to access specific resources. It includes the issuance and validation of attribute certificates. Public-key certificates are certificates for trusting public-key, while attribute certificates are certificates for trusting privilege attribute. In the practical cases, when the system identifies a user´s identity, it allocates the right permissions to the resources to the user according to the roles he/she played. This permission control mechanism is called the role-based access control (RBAC). This paper addresses an efficient privilege management mechanism, based on PMI and RBAC, to achieve the information security objectives of non-repudiation, integrity, and security. A security model is built to solve problems of privilege management and duty delegation.
Keywords :
Access control; Authentication; Certification; Computer science; Computer security; Data security; Information security; Permission; Public key; Resource management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security Technology, 2005. CCST '05. 39th Annual 2005 International Carnahan Conference on
Print_ISBN :
0-7803-9245-0
Type :
conf
DOI :
10.1109/CCST.2005.1594859
Filename :
1594859
Link To Document :
بازگشت