DocumentCode :
339892
Title :
Efficient large-scale access control for Internet/intranet information systems
Author :
Qi Lu ; Shang-Hua Teng
Author_Institution :
IBM Almaden Res. Center, San Jose, CA, USA
Volume :
Track5
fYear :
1999
fDate :
5-8 Jan. 1999
Abstract :
Access control is a key problem for information processing, especially in a distributed environment such as the Internet and intranet, where a large amount of diverse information resources within an enterprise will be made available for groups of diverse users to query. Information documents such as technology secrets and personal records are sensitive and should be accessible to a select group of users based on their position in a company or an organization or even based on how much the user is paying to maintain his/her right for information access. The access control problem, informally, is to determine which user is allowed to access what information. Access control for Internet information processing, in contrast to access control in a traditional operating system, has higher demand in dealing with a much larger scale problem in real time, due to the large amount of information and number of users in the Internet/intranet environment. We present an efficient method for the access control problem in which there are a large number of users and access groups. The main ingredient of our method is a representation of a hierarchical access group structure in terms of intervals over a set of integers and a decomposition scheme that reduces any group structure to ones that have interval representations. The interval representation allows the problem for checking access rights to be reduced to an interval containment problem. We use the interval tree, a popular data structure in computational geometry, to efficiently execute the access-right checking method.
Keywords :
Internet; authorisation; information resources; intranets; tree data structures; Internet; access-right checking method; data structure; decomposition scheme; enterprise; hierarchical access group structure; information access; information processing; information resources; information systems; interval containment problem; interval tree; intranet; large-scale access control; operating system; personal records; real time; Access control; Companies; Information processing; Information resources; Internet; Large-scale systems; Operating systems; Permission; Real time systems; Tree data structures;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systems Sciences, 1999. HICSS-32. Proceedings of the 32nd Annual Hawaii International Conference on
Conference_Location :
Maui, HI, USA
Print_ISBN :
0-7695-0001-3
Type :
conf
DOI :
10.1109/HICSS.1999.772944
Filename :
772944
Link To Document :
بازگشت