• DocumentCode
    2027612
  • Title

    dRBAC: distributed role-based access control for dynamic coalition environments

  • Author

    Freudenthal, Eric ; Pesin, Tracy ; Port, Lawrence ; Keenan, Edward ; Karamcheti, Vijay

  • Author_Institution
    Dept. of Comput. Sci., New York Univ., NY, USA
  • fYear
    2002
  • fDate
    2002
  • Firstpage
    411
  • Lastpage
    420
  • Abstract
    distributed role-based access control (dRBAC) is a scalable, decentralized trust-management and access-control mechanism for systems that span multiple administrative domains. dRBAC utilizes PKI identities to define trust domains, roles to define controlled activities, and role delegation across domains to represent permissions to these activities. The mapping of controlled actions to roles enables their namespaces to serve as policy roots. dRBAC distinguishes itself from previous approaches by providing three features: (1) third-party delegation of roles from outside a domain´s namespace, relying upon an explicit delegation of assignment; (2) modulation of transferred permissions using scalar valued attributes associated with roles; and (3) continuous monitoring of trust relationships over long-lived interactions. The paper describes the dRBAC model and its scalable implementation using a graph approach to credential discovery and validation.
  • Keywords
    authorisation; distributed processing; PKI identities; continuous monitoring; controlled activities; credential discovery; credential validation; dRBAC; distributed role-based access control; dynamic coalition environments; graph approach; long-lived interactions; multiple administrative domains; namespaces; policy roots; role delegation; scalable decentralized access control mechanism; scalable decentralized trust-management mechanism; scalar valued attributes; third-party delegation; transferred permissions; trust domains; trust relationships; Access control; Authorization; Computer science; Computerized monitoring; Control systems; Feeds; IP networks; Permission; Protection; Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems, 2002. Proceedings. 22nd International Conference on
  • ISSN
    1063-6927
  • Print_ISBN
    0-7695-1585-1
  • Type

    conf

  • DOI
    10.1109/ICDCS.2002.1022279
  • Filename
    1022279