Fine-grained integration of access control policies

被引:19
|
作者
Rao, Prathima [1 ]
Lin, Dan [2 ]
Bertino, Elisa [1 ]
Li, Ninghui [1 ]
Lobo, Jorge [3 ]
机构
[1] Purdue Univ, Dept Comp Sci, W Lafayette, IN 47907 USA
[2] Missouri Univ Sci & Technol, Dept Comp Sci, Rolla, MO USA
[3] IBM TJ Watson Res Ctr, Yorktown Hts, NY USA
关键词
Access control; Algebra; Framework; Policy integration; XACML;
D O I
10.1016/j.cose.2010.10.006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Collaborative and distributed applications, such as dynamic coalitions and virtualized grid computing, often require integrating access control policies of collaborating parties. Such an integration must be able to support complex authorization specifications and the fine-grained integration requirements that the various parties may have. In this paper, we introduce an algebra for fine-grained integration of sophisticated policies. The algebra, which consists of three binary and two unary operations, is able to support the specification of a large variety of integration constraints. For ease of use, we also introduce a set of derived operators and provide guidelines for users to edit a policy with desired properties. To assess the expressive power of our algebra, we define notion of completeness and prove that our algebra is complete and minimal with respect to the notion. We then propose a framework that uses the algebra for the fine-grained integration of policies expressed in XACML. We also present a methodology for generating the actual integrated XACML policy, based on the notion of Multi-Terminal Binary Decision Diagrams. Experimental results have demonstrated both effectiveness and efficiency of our approach. In addition, we also discuss issues regarding obligations. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:91 / 107
页数:17
相关论文
共 50 条
  • [1] Modelling Fine-Grained Access Control Policies in Grids
    Benjamin Aziz
    Journal of Grid Computing, 2016, 14 : 477 - 493
  • [2] Modelling Fine-Grained Access Control Policies in Grids
    Aziz, Benjamin
    JOURNAL OF GRID COMPUTING, 2016, 14 (03) : 477 - 493
  • [3] Fine-Grained Disclosure of Access Policies
    Ardagna, Claudio Agostino
    di Vimercati, Sabrina De Capitani
    Foresti, Sara
    Neven, Gregory
    Paraboschi, Stefano
    Preiss, Franz-Stefan
    Samarati, Pierangela
    Verdicchio, Mario
    INFORMATION AND COMMUNICATIONS SECURITY, 2010, 6476 : 16 - +
  • [4] Fine-grained cooperative access control scheme with hidden policies
    Gang H.
    Qixuan X.
    Yinghui Z.
    Journal of China Universities of Posts and Telecommunications, 2021, 28 (06): : 13 - 25
  • [5] Fine-grained cooperative access control scheme with hidden policies
    Han Gang
    Xing Qixuan
    Zhang Yinghui
    TheJournalofChinaUniversitiesofPostsandTelecommunications, 2021, 28 (06) : 13 - 25
  • [6] Capturing policies for fine-grained access control on mobile devices
    Das, Prajit Kumar
    Joshi, Anupam
    Finin, Tim
    2016 IEEE 2ND INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (IEEE CIC), 2016, : 54 - 63
  • [7] An Algebra for Fine-Grained Integration of XACML Policies
    Rao, Prathima
    Lin, Dan
    Bertino, Elisa
    Li, Ninghui
    Lobo, Jorge
    SACMAT'09: PROCEEDINGS OF THE 14TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, 2009, : 63 - 72
  • [8] Efficient integration of fine-grained access control and resource brokering in grid
    P. Mazzoleni
    B. Crispo
    S. Sivasubramanian
    E. Bertino
    The Journal of Supercomputing, 2009, 49
  • [9] Fine-Grained Access Control for Microservices
    Nehme, Antonio
    Jesus, Vitor
    Mahbub, Khaled
    Abdallah, Ali
    FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2018, 2019, 11358 : 285 - 300
  • [10] Efficient integration of fine-grained access control and resource brokering in grid
    Mazzoleni, P.
    Crispo, B.
    Sivasubramanian, S.
    Bertino, E.
    JOURNAL OF SUPERCOMPUTING, 2009, 49 (01): : 108 - 126