dRBAC: Distributed role-based access control for dynamic coalition environments

被引:76
作者
Freudenthal, E [1 ]
Pesin, T [1 ]
Port, L [1 ]
Keenan, E [1 ]
Karamcheti, V [1 ]
机构
[1] NYU, Dept Comp Sci, New York, NY 10012 USA
来源
22ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, PROCEEDINGS | 2002年
关键词
D O I
10.1109/ICDCS.2002.1022279
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Distributed Role-Based Access Control (dRBAC) is a scalable, decentralized trust-management and access-control mechanism for systems that span multiple administrative domains. dRBAC utilizes PKI identities to define trust domains, roles to define controlled activities, and role delegation across domains to represent permissions to these activities. The mapping of controlled actions to roles enables their namespaces to serve as policy roots. dRBAC distinguishes itself from previous approaches by providing three features: (1) third-party delegation of roles from outside a domain's namespace, relying upon an explicit delegation of assignment; (2) modulation of transferred permissions using scalar valued attributes associated with roles; and (3) continuous monitoring of trust relationships over long-lived interactions. This paper describes the dRBAC model and its scalable implementation using a graph approach to credential discovery and validation.
引用
收藏
页码:411 / 420
页数:10
相关论文
共 17 条
[1]  
AIELLO W, 1998, P CRYPTO 98
[2]  
BLAZE M, 1996, P IEEE C PRIV SEC
[3]  
BLAZE M, 1998, P SEC PROT INT WORKS
[4]  
Chen R., 2001, Poblano A Distributed Trust Model for Peer-to-Peer Networks
[5]  
CLARKE D, 1999, CERTIFICATE CHAIN DI
[6]  
ELLISON C, 1998, SPKI CERTIFICATE THE
[7]  
FREUDENTHAL E, 2002, IN PRESS P IEEE WORK
[8]  
FREUDENTHAL E, 2001, 2001820 NEW YORK U
[9]  
Housley R., 1999, INTERNET X 509 PUBLI
[10]  
HOWELL J, 2000, P USENIX S OP SYST D