Achieving fine-grained access control in virtual organizations

被引:4
|
作者
Zhang, N.
Yao, L.
Nenadic, A.
Chin, J.
Goble, C.
Rector, A.
Chadwick, D.
Otenko, S.
Shi, Q.
机构
[1] Univ Manchester, Sch Comp Sci, Manchester M13 9PL, Lancs, England
[2] Univ Kent, Comp Lab, Canterbury CT2 7NF, Kent, England
[3] Liverpool John Moores Univ, Sch Comp & Math Sci, Liverpool L3 3AF, Merseyside, England
来源
基金
英国工程与自然科学研究理事会;
关键词
authentication; authorization; virtual organization; Shibboleth; PERMIS; smart tokens;
D O I
10.1002/cpe.1099
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In a virtual organization environment, where services and data are provided and shared among organizations from different administrative domains and protected with dissimilar security policies and measures, there is a need for a flexible authentication framework that supports the use of various authentication methods and tokens. The authentication strengths derived from the authentication methods and tokens should be incorporated into an access-control decision-making process, so that more sensitive resources are available only to users authenticated with stronger methods. This paper reports our ongoing efforts in designing and implementing such a framework to facilitate multi-level and multi-factor adaptive authentication and authentication strength linked fine-grained access control. The proof-of-concept prototype is designed and implemented in the Shibboleth and PERMIS infrastructures, which specifies protocols to federate authentication and authorization information and provides a policy-driven, role-based, access-control decision-making capability. Copyright (c) 2006 John Wiley & Sons, Ltd.
引用
收藏
页码:1333 / 1352
页数:20
相关论文
共 50 条
  • [1] Achieving fine-grained access control and integrity auditing in cloud storage
    Yuan, S. (ysm1005@163.com), 1600, Binary Information Press, P.O. Box 162, Bethel, CT 06801-0162, United States (09):
  • [2] Achieving Fine-Grained Data Sharing for Hierarchical Organizations in Clouds
    Deng, Hua
    Qin, Zheng
    Wu, Qianhong
    Deng, Robert H.
    Guan, Zhenyu
    Hu, Yupeng
    Li, Fangmin
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (02) : 1364 - 1377
  • [3] Achieving Secure, Scalable, and Fine-grained Data Access Control in Cloud Computing
    Yu, Shucheng
    Wang, Cong
    Ren, Kui
    Lou, Wenjing
    2010 PROCEEDINGS IEEE INFOCOM, 2010,
  • [4] Achieving Revocable Fine-Grained Cryptographic Access Control over Cloud Data
    Yang, Yanjiang
    Ding, Xuhua
    Lu, Haibing
    Wan, Zhiguo
    Zhou, Jianying
    INFORMATION SECURITY (ISC 2013), 2015, 7807 : 293 - 308
  • [5] Fine-Grained Access Control for Microservices
    Nehme, Antonio
    Jesus, Vitor
    Mahbub, Khaled
    Abdallah, Ali
    FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2018, 2019, 11358 : 285 - 300
  • [6] AB-PAKE: Achieving Fine-Grained Access Control and Flexible Authentication
    Song, Mi
    Wang, Ding
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6197 - 6212
  • [7] Achieving fine-grained access control for secure data sharing on cloud servers
    Wang, Guojun
    Liu, Qin
    Wu, Jie
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2011, 23 (12): : 1443 - 1464
  • [8] Toward Achieving Fine-Grained Access Control of Data in Connected and Autonomous Vehicles
    Cui, Jie
    Chen, Xuelian
    Zhang, Jing
    Zhang, Qingyang
    Zhong, Hong
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (10) : 7925 - 7937
  • [9] Achieving Fine-Grained Access Control with Discretionary User Revocation over Cloud Data
    Dong, Qiuxiang
    Huang, Dijiang
    Luo, Jim
    Kang, Myong
    2018 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2018,
  • [10] Achieving fine-grained access control and mitigating role explosion by utilising ABE with RBAC
    Balusamy B.
    Ramachandran S.
    Priya N.
    International Journal of High Performance Computing and Networking, 2017, 10 (1-2) : 109 - 117