• DocumentCode
    2295664
  • Title

    xDUCON: Coordinating Usage Control Policies in Distributed Domains

  • Author

    Russello, Giovanni ; Dulay, Naranker

  • Author_Institution
    Create-net, Trento, Italy
  • fYear
    2009
  • fDate
    19-21 Oct. 2009
  • Firstpage
    246
  • Lastpage
    253
  • Abstract
    In this paper, we present xDUCON a framework for coordinating and enforcing usage control policies across different collaborating organisations. xDUCON allows the specification of usage control policies that concisely capture conditions, authorisations, and obligations on both providers and consumers of resources. The xDUCON framework is based on the Shared Data Space (SDS) abstraction, where collaborating organisations share a data space containing tuples representing subjects, resources and usage policies. The SDS allows the coordination of the decision and enforcement points abstracting from the details of the actual deployment of the framework. As a consequence, xDUCON supports policies able to express richer and finer constraints compared to previous usage control models. Policies support entity mutability that is the changing of related subject and target attributes due to accesses being executed. The decision and enforcement points support ongoing control over long-lived sessions to evaluate the access rights of a subject while the access is being executed. If the context under which the rights were granted changes, xDUCON is able to revoke the access rights preventing the subject to use any longer the resource.
  • Keywords
    authorisation; distributed programming; formal specification; resource allocation; access right; authorisation; collaborating organisation; distributed domain; entity mutability; resource use; shared data space abstraction; target attribute; usage control policy coordination specification; xDSpace Programming; xDUCON framework; Authorization; Companies; Computer networks; Control systems; Disaster management; Distributed computing; Distributed control; Information management; International collaboration; Permission; Cross domain policy enforcement; Shared Data Space; Usage control policies;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security, 2009. NSS '09. Third International Conference on
  • Conference_Location
    Gold Coast, QLD
  • Print_ISBN
    978-1-4244-5087-9
  • Electronic_ISBN
    978-0-7695-3838-9
  • Type

    conf

  • DOI
    10.1109/NSS.2009.77
  • Filename
    5319024