DocumentCode
2027612
Title
dRBAC: distributed role-based access control for dynamic coalition environments
Author
Freudenthal, Eric ; Pesin, Tracy ; Port, Lawrence ; Keenan, Edward ; Karamcheti, Vijay
Author_Institution
Dept. of Comput. Sci., New York Univ., NY, USA
fYear
2002
fDate
2002
Firstpage
411
Lastpage
420
Abstract
distributed role-based access control (dRBAC) is a scalable, decentralized trust-management and access-control mechanism for systems that span multiple administrative domains. dRBAC utilizes PKI identities to define trust domains, roles to define controlled activities, and role delegation across domains to represent permissions to these activities. The mapping of controlled actions to roles enables their namespaces to serve as policy roots. dRBAC distinguishes itself from previous approaches by providing three features: (1) third-party delegation of roles from outside a domain´s namespace, relying upon an explicit delegation of assignment; (2) modulation of transferred permissions using scalar valued attributes associated with roles; and (3) continuous monitoring of trust relationships over long-lived interactions. The paper describes the dRBAC model and its scalable implementation using a graph approach to credential discovery and validation.
Keywords
authorisation; distributed processing; PKI identities; continuous monitoring; controlled activities; credential discovery; credential validation; dRBAC; distributed role-based access control; dynamic coalition environments; graph approach; long-lived interactions; multiple administrative domains; namespaces; policy roots; role delegation; scalable decentralized access control mechanism; scalable decentralized trust-management mechanism; scalar valued attributes; third-party delegation; transferred permissions; trust domains; trust relationships; Access control; Authorization; Computer science; Computerized monitoring; Control systems; Feeds; IP networks; Permission; Protection; Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Distributed Computing Systems, 2002. Proceedings. 22nd International Conference on
ISSN
1063-6927
Print_ISBN
0-7695-1585-1
Type
conf
DOI
10.1109/ICDCS.2002.1022279
Filename
1022279
Link To Document