• DocumentCode
    2953088
  • Title

    Identity Delegation in Policy Based Systems

  • Author

    Gupta, Rajeev ; Roy, Shourya ; Bhide, Manish

  • Author_Institution
    IBM, New Delhi
  • fYear
    2007
  • fDate
    13-15 June 2007
  • Firstpage
    229
  • Lastpage
    240
  • Abstract
    Policy based systems have received considerable attention in the recent past from academia as well as the industry. Research on policy based systems encompasses a gamut of areas such as: models and languages for policy based systems, policy standards, domain specific implementations, policy tools etc. However an important issue, which did not receive much attention from researchers, is that of access control for policy execution. In this paper we present the concept of "identity delegation" which involves finding the \´correct\´ users/ identities, to whom task of policy execution can be delegated. Policies are generally defined by high level business executives (policy authors) and are implemented by policy enforcers who have sufficient access rights on the underlying systems. Given the increasing complexity of enterprise systems, we show in this paper that finding the right policy enforcers for a policy can be a fairly non-trivial task. We address this important problem by proposing a unique concept of \´implicit identity delegation\´, whereby an autonomic system automatically figures out the correct policy enforcers and implicitly delegates the task of policy execution. We present the Implicit Identity Delegation architecture which boasts of an efficient technique for performing implicit identity delegation and uses a plugin based architecture ensuring its applicability and use in diverse domains.
  • Keywords
    authorisation; access control; enterprise systems; implicit identity delegation architecture; policy based systems; policy execution; policy standards; Access control; Databases; Decision making; Electrical equipment industry; Gold; High level languages; Natural languages; Permission; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks, 2007. POLICY '07. Eighth IEEE International Workshop on
  • Conference_Location
    Bologna
  • Print_ISBN
    0-7695-2767-1
  • Type

    conf

  • DOI
    10.1109/POLICY.2007.26
  • Filename
    4262592