• DocumentCode
    1900479
  • Title

    Distributed Access Control Model over Multi-trust Domain

  • Author

    Huang Kun ; Yao Jing ; Dong Xiaoming ; Wang Lu

  • Author_Institution
    China Ship Dev. & Design Center, Wuhan, China
  • Volume
    2
  • fYear
    2012
  • fDate
    23-25 March 2012
  • Firstpage
    595
  • Lastpage
    598
  • Abstract
    In the current information system which is highl dynamic, heterogeneous and distributed, it is necessary to realizing information-sharing and interoperation among multi-trust domains securely by a crossing single-domain restriction. This thesis analyses the basic idea of the IRBAC (Interoperability Role Based Access Control) 2000 model, then points out several existing problems in them, which are showed as follows: (1) it violates the principle of duty separateness during role mapping among multi-trust domain; (2) it dose not consider how to process the related role when roles enter or exit. To solve the above problems, the MTD-EIRBAC model is proposed. With the introduction of the trust-level computing and granular logical reasoning, the dynamic authorization of the MTD-EIRBAC model is realized, and the problems of both the related role processing while roles changes (role enter or exit), and the role infiltration while the role shuttles the other domains are properly resolved. The safe and flexible collaboration of multi-trust domains is maken possible.
  • Keywords
    authorisation; data privacy; inference mechanisms; information management; information systems; open systems; IRBAC 2000 model; distributed access control model; duty separateness principle; dynamic authorization; granular logical reasoning; information sharing; information system; interoperability role based access control; interoperation; multitrust domain; role mapping; role processing; single-domain restriction; trust-level computing; Analytical models; Authentication; Authorization; Computational modeling; Servers; Access Control; Multi-Trust Domain; Role Granularity/Authority Granularity; Trust rank; styling;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Science and Electronics Engineering (ICCSEE), 2012 International Conference on
  • Conference_Location
    Hangzhou
  • Print_ISBN
    978-1-4673-0689-8
  • Type

    conf

  • DOI
    10.1109/ICCSEE.2012.34
  • Filename
    6188101