Double-Tier Role and Organization-Based Cross-Domain Access Control Mechanism

H. Xiong, Xing-yuan Chen, Xuehui Du, Yan Yang
{"title":"Double-Tier Role and Organization-Based Cross-Domain Access Control Mechanism","authors":"H. Xiong, Xing-yuan Chen, Xuehui Du, Yan Yang","doi":"10.1109/ISCID.2014.251","DOIUrl":null,"url":null,"abstract":"Aiming at the deficiencies of weak adaptability due to the singleness of the role establishment method, relatively high management complexity and the security problems such as covert role promotion and privilege penetration in the existing methods, a double-tier role and organization-based cross-domain access control mechanism is proposed. The double-tier role architecture of function role and task role resolves the problem that traditional concept of role couldn't cover the requirements of both organizational level and application level at the same time and meets the practical needs of role establishment with strong adaptability. A scalable double-tier role and organization-based access control model (DTR-OBAC) is put forward and defined formally based on the double-tier role architecture and organization. The concept of virtual sharing organization is introduced and treated as the common subordinate organization of participating domains. The cross-domain access control mechanism is present based on DTR-OBAC model and virtual sharing organization, to achieve security interoperation. The practicability and feasibility is verified with an example and the features are analyzed, indicating that the mechanism meets the principles of autonomy and security in interoperation.","PeriodicalId":385391,"journal":{"name":"2014 Seventh International Symposium on Computational Intelligence and Design","volume":"407 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-12-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 Seventh International Symposium on Computational Intelligence and Design","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISCID.2014.251","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Aiming at the deficiencies of weak adaptability due to the singleness of the role establishment method, relatively high management complexity and the security problems such as covert role promotion and privilege penetration in the existing methods, a double-tier role and organization-based cross-domain access control mechanism is proposed. The double-tier role architecture of function role and task role resolves the problem that traditional concept of role couldn't cover the requirements of both organizational level and application level at the same time and meets the practical needs of role establishment with strong adaptability. A scalable double-tier role and organization-based access control model (DTR-OBAC) is put forward and defined formally based on the double-tier role architecture and organization. The concept of virtual sharing organization is introduced and treated as the common subordinate organization of participating domains. The cross-domain access control mechanism is present based on DTR-OBAC model and virtual sharing organization, to achieve security interoperation. The practicability and feasibility is verified with an example and the features are analyzed, indicating that the mechanism meets the principles of autonomy and security in interoperation.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
基于双层角色和组织的跨域访问控制机制
针对现有角色建立方法单一适应性弱、管理复杂性较高以及角色隐蔽提升、权限渗透等安全问题,提出了一种基于双层角色和组织的跨域访问控制机制。功能角色和任务角色的双层角色架构解决了传统角色概念无法同时覆盖组织层和应用层需求的问题,以较强的适应性满足了角色建立的实际需要。基于双层角色体系结构和组织结构,提出并正式定义了可扩展的双层角色和基于组织的访问控制模型(DTR-OBAC)。引入了虚拟共享组织的概念,并将其视为参与域的共同下属组织。提出了基于DTR-OBAC模型和虚拟共享组织的跨域访问控制机制,实现了安全互操作。通过实例验证了该机制的实用性和可行性,并对其特点进行了分析,表明该机制符合互操作的自主性和安全性原则。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
An Integrated Framework for Analysis and Mining of the Massive Sensor Data Using Feature Preserving Strategy on Cloud Computing Acetylene Density Measurement System Based on Differential and Harmonic Detection Research Intelligent Fire Evacuation System Based on Ant Colony Algorithm and MapX Research on the Application of Intelligent Campus Supermarket System -- Based on the Internet of Things (IOT) Technology Speaker Recognition Method Based on CPSO Clustering and KMP Algorithm
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1