DocumentCode :
969871
Title :
X-FEDERATE: a policy engineering framework for federated access management
Author :
Bhatti, Rafae ; Bertino, Elisa ; Ghafoor, Arif
Author_Institution :
Dept. of Electr. & Comput. Eng., Purdue Univ., West Lafayette, IN
Volume :
32
Issue :
5
fYear :
2006
fDate :
5/1/2006 12:00:00 AM
Firstpage :
330
Lastpage :
346
Abstract :
Policy-based management (PBM) has been considered as a promising approach for design and enforcement of access management policies for distributed systems. The increasing shift toward federated information sharing in the organizational landscape, however, calls for revisiting current PBM approaches to satisfy the unique security requirements of the federated paradigm. This presents a twofold challenge for the design of a PBM approach, where, on the one hand, the policy must incorporate the access management needs of the individual systems, while, on the other hand, the policies across multiple systems must be designed in such a manner that they can be uniformly developed, deployed, and integrated within the federated system. In this paper, we analyze the impact of security management challenges on policy design and formulate a policy engineering methodology based on principles of software engineering to develop a PBM solution for federated systems. We present X-FEDERATE, a policy engineering framework for federated access management using an extension of the well-known role-based access control (RBAC) model. Our framework consists of an XML-based policy specification language, its UML-based meta-model, and an enforcement architecture. We provide a comparison of our framework with related approaches and highlight its significance for federated access management. The paper also presents a federation protocol and discusses a prototype of our framework that implements the protocol in a federated digital library environment
Keywords :
Unified Modeling Language; XML; authorisation; data models; digital libraries; software architecture; UML-based meta-model; X-FEDERATE; XML-based policy specification language; distributed systems; enforcement architecture; federated access management; federated digital library environment; federated information sharing; policy engineering framework; policy-based management; role-based access control; security management; Access control; Access protocols; Computer architecture; Design engineering; Engineering management; Information security; Prototypes; Software development management; Software engineering; Specification languages; Federated systems; role-based access control.; security management; software engineering;
fLanguage :
English
Journal_Title :
Software Engineering, IEEE Transactions on
Publisher :
ieee
ISSN :
0098-5589
Type :
jour
DOI :
10.1109/TSE.2006.49
Filename :
1642680
Link To Document :
بازگشت