Title :
Enforcing Separation of Duty in Ad Hoc Collaboration
Author :
Deng, Lingli ; He, Yeping ; Xu, Ziyao
Author_Institution :
Inst. of Software, Chinese Acad. of Sci., Beijing
Abstract :
By collaboration, domains share resources effectively. To maintain security properties of individual domains during collaboration is a key issue. When domains employing heterogeneous RBAC policies collaborate by crossdomain role-role mappings, their local SMER constraints may be violated. However, the secure interoperation studied so far does not deal with this threat. We presents the requirement for constraint secure interoperation, prohibiting implicit authorizations that break constraints of other member domain. We propose a framework for crossdomain constraint enforcement in dynamic mediator-free ad hoc collaboration. By introducing crossdomain migration of MD-SMERs, the framework ensures the global security in terms of SMERs from individual domains. Specifically, we introduce a bitmap-based history-recording mechanism for collaborating domains to analyze the interplay among innerdomain role hierarchies, crossdomain role-role mappings, and SMER constraints. Algorithms of a fully distributed implementation for the framework and its security proofs are given.
Keywords :
ad hoc networks; authorisation; groupware; telecommunication security; RBAC policy; bitmap-based history-recording mechanism; constraint secure interoperation; crossdomain constraint enforcement; crossdomain role-role mappings; dynamic mediator-free ad hoc collaboration; Access control; Authorization; Collaborative software; Data security; Helium; IP networks; Information security; International collaboration; Peer to peer computing; Resource management; Secure collaboration; role-based access control; separation of duty; statically mutually exclusive roles;
Conference_Titel :
Young Computer Scientists, 2008. ICYCS 2008. The 9th International Conference for
Conference_Location :
Hunan
Print_ISBN :
978-0-7695-3398-8
Electronic_ISBN :
978-0-7695-3398-8
DOI :
10.1109/ICYCS.2008.131