DocumentCode :
1408230
Title :
Towards an authorisation model for distributed systems based on the Semantic Web
Author :
Alcaraz Calero, Jose M. ; Martinez Perez, Gregorio ; Gomez Skarmeta, A.F.
Volume :
4
Issue :
4
fYear :
2010
fDate :
12/1/2010 12:00:00 AM
Firstpage :
411
Lastpage :
421
Abstract :
Authorisation is a crucial process in current information systems. Nowadays, many of the current authorisation systems do not provide methods to describe the semantics of the underlying information model which they are protecting. This fact can lead to mismatch problems between the semantics of the authorisation model and the semantics of the underlying data and resources being protected. In order to solve this problem, this paper describes an authorisation model based on Semantic Web technologies. This authorisation model uses the common information model (CIM) to represent the underlying information model. For this reason, a new conversion process of CIM into the Semantic Web languages has been proposed converting properly the semantics available in the CIM model. This representation provides a suitable information model based on a well-known logic formalism for implementing the authorisation model and a formal language for describing concisely the semantic of the information models being protected. The formal authorisation model supports role-based access control (RBAC), hierarchical RBAC, conditional RBAC and object hierarchies, among other features. Moreover, this paper describes an authorisation architecture for distributed systems taking into account aspects such as privacy among parties and trust management. Finally, some implementation aspects of this system have also been described.
Keywords :
authorisation; data privacy; formal logic; semantic Web; CIM conversion process; authorisation model; common information model; conditional RBAC; distributed systems; hierarchical RBAC; information systems; logic formalism; object hierarchies; party privacy; role-based access control; semantic Web; trust management;
fLanguage :
English
Journal_Title :
Information Security, IET
Publisher :
iet
ISSN :
1751-8709
Type :
jour
DOI :
10.1049/iet-ifs.2009.0260
Filename :
5672454
Link To Document :
بازگشت