DocumentCode
3238412
Title
Cryptographic Roles in the Age of Wikileaks: Implementation Models for Cryptographically Enforced RBAC
Author
Kiviharju, Mikko
Author_Institution
Finnish Defence Forces Tech. Res. Centre, Riihimaki, Finland
fYear
2013
fDate
18-20 Nov. 2013
Firstpage
1779
Lastpage
1788
Abstract
Role-based access control (RBAC) is the de facto access control model used in current information systems, also in military environments. This is because RBAC can be used to describe multi-level secure access control (AC) policies so common in military environments handling information from multiple levels of classification. Cryptographic access control (CAC), on the other hand, is an implementation paradigm intended to enforce AC policies cryptographically. CAC-methods are also attractive in military cloud and tactical environments due to their distributed and offline nature of operation. Combining the capabilities of both RBAC and CAC fully seems elusive, though. This paper studies the feasibility of implementing RBAC with respect to read-rights using a recent type of cryptographic schemes called attribute-based encryption (ABE). We present an implementation model based on the Extensible Access Control Markup Language (XACML) reference architecture and evaluate how the current state ABE can realize the different RBAC standard model components. We will show that it is feasible to implement at least the Core RBAC with standard XACML architecture and ABE models, and that the expressiveness of the ABE-schemes can reach nearly all the way in terms of symmetric RBAC commands and functions, such as Dynamic Separation of Duty.
Keywords
access control; cryptography; military computing; ABE; CAC-method; RBAC; Wikileaks; XACML architecture; attribute-based encryption; cryptographic access control; de facto access control model; extensible access control markup language; military environment; multilevel secure AC-policies; role-based access control; tactical environment; Access control; Encryption; Monitoring; Permission; Standards; ABE; Access Control; CBIS; Cryptography; MLS; RBAC;
fLanguage
English
Publisher
ieee
Conference_Titel
Military Communications Conference, MILCOM 2013 - 2013 IEEE
Conference_Location
San Diego, CA
Type
conf
DOI
10.1109/MILCOM.2013.301
Filename
6735883
Link To Document