Achieving fine-grained access control in virtual organizations

被引:4
|
作者
Zhang, N.
Yao, L.
Nenadic, A.
Chin, J.
Goble, C.
Rector, A.
Chadwick, D.
Otenko, S.
Shi, Q.
机构
[1] Univ Manchester, Sch Comp Sci, Manchester M13 9PL, Lancs, England
[2] Univ Kent, Comp Lab, Canterbury CT2 7NF, Kent, England
[3] Liverpool John Moores Univ, Sch Comp & Math Sci, Liverpool L3 3AF, Merseyside, England
来源
基金
英国工程与自然科学研究理事会;
关键词
authentication; authorization; virtual organization; Shibboleth; PERMIS; smart tokens;
D O I
10.1002/cpe.1099
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In a virtual organization environment, where services and data are provided and shared among organizations from different administrative domains and protected with dissimilar security policies and measures, there is a need for a flexible authentication framework that supports the use of various authentication methods and tokens. The authentication strengths derived from the authentication methods and tokens should be incorporated into an access-control decision-making process, so that more sensitive resources are available only to users authenticated with stronger methods. This paper reports our ongoing efforts in designing and implementing such a framework to facilitate multi-level and multi-factor adaptive authentication and authentication strength linked fine-grained access control. The proof-of-concept prototype is designed and implemented in the Shibboleth and PERMIS infrastructures, which specifies protocols to federate authentication and authorization information and provides a policy-driven, role-based, access-control decision-making capability. Copyright (c) 2006 John Wiley & Sons, Ltd.
引用
收藏
页码:1333 / 1352
页数:20
相关论文
共 50 条
  • [31] A fine-grained access control and revocation scheme on clouds
    Tu, Shan-shan
    Niu, Shao-zhang
    Li, Hui
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2016, 28 (06): : 1697 - 1714
  • [33] Modelling Fine-Grained Access Control Policies in Grids
    Benjamin Aziz
    Journal of Grid Computing, 2016, 14 : 477 - 493
  • [34] Vigiles: Fine-grained Access Control for MapReduce Systems
    Ulusoy, Huseyin
    Kantarcioglu, Murat
    Pattuk, Erman
    Hamlen, Kevin
    2014 IEEE INTERNATIONAL CONGRESS ON BIG DATA (BIGDATA CONGRESS), 2014, : 40 - 47
  • [35] Fine-grained access control for EPC information services
    Grummt, Eberhard
    Mueller, Markus
    INTERNET OF THINGS, PROCEEDINGS, 2008, 4952 : 35 - +
  • [36] A fine-grained access control model for relational databases
    Jie Shi
    Hong Zhu
    Journal of Zhejiang University SCIENCE C, 2010, 11 : 575 - 586
  • [37] A fine-grained access control model for Web services
    Bertino, E
    Squicciarini, AC
    Mevi, D
    2004 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, PROCEEDINGS, 2004, : 33 - 40
  • [38] Modelling Fine-Grained Access Control Policies in Grids
    Aziz, Benjamin
    JOURNAL OF GRID COMPUTING, 2016, 14 (03) : 477 - 493
  • [39] THE RESEARCH OF SPREADSHEET BASED ON FINE-GRAINED ACCESS CONTROL
    Zheng Yanwei
    Feng Zhiquan
    FIFTH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER THEORY AND ENGINEERING (ICACTE 2012), 2012, : 245 - 251
  • [40] A Fine-grained Access Control Model for Knowledge Graphs
    Valzelli, Marco
    Maurino, Andrea
    Palmonari, Matteo
    PROCEEDINGS OF THE 17TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (SECRYPT), VOL 1, 2020, : 595 - 601