A dynamic access control model for inter-operation in multi-domain environment based on risk

被引:0
|
作者
Tang, Zhuo [1 ,2 ]
Zhao, Lin [1 ]
Li, Kenli [1 ]
Li, Ruixuan [2 ]
机构
[1] College of Computer and Communication, Hunan University, Changsha 410082, China
[2] School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China
关键词
Access control models - Safety factor;
D O I
暂无
中图分类号
学科分类号
摘要
The rapid development of Internet and related technologies has created tremendous possibilities for the interoperability between applications in open and heterogeneous distributed environment. Interoperability provides a means for distributed applications to share resources and services, which improves performance and resource utilization. Access control is a crucial security technology. It can control the legal users to sensitive resources effectively and ensure users to access relative resource. For the complexity of the multi-domain environment and the ceaseless evolvement of the information secure share, the traditional access control method can not ensure the absolute security for the exchange of data resource. Traditional access control model can not satisfy the requirement of the dynamic of the multi-domain environment. Through introducing the concept of risk, the authors propose a dynamic access control model for multi-domain environment based on the risk of inter-operations. The risk grade of an access policy can be calculated by the history of the inter-operations among domains; the security degree of the objects and the safety factor of the access events. Through adjusting the access policies which have high risk grade, the risk in the system can be controlled in real time. The analysis of the security theory shows that this method can reinforce the facility of the access control and the security of the multi-domain environment.
引用
收藏
页码:948 / 955
相关论文
共 50 条
  • [1] Dynamic access control research for inter-operation in multi-domain environment based on risk
    Tang, Zhuo
    Li, Ruixuan
    Lu, Zhengding
    Wen, Zhumu
    INFORMATION SECURITY APPLICATIONS, 2007, 4867 : 277 - 290
  • [3] Verification of Secure Inter-operation Properties in Multi-domain RBAC Systems
    Gouglidis, Antonios
    Mavridis, Ioannis
    Hu, Vincent C.
    2013 IEEE 7TH INTERNATIONAL CONFERENCE ON SOFTWARE SECURITY AND RELIABILITY - COMPANION (SERE-C), 2013, : 36 - 45
  • [4] Trust-based Access Control Model in Multi-domain Environment
    Zhang Qikun
    Wang Ruifang
    Qu Jiaqing
    Gan Yong
    Zheng Jun
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (05): : 149 - 160
  • [5] Role-Based Access Control Model for Inter-System Cross-Domain in Multi-Domain Environment
    Li, Yunliang
    Du, Zhiqiang
    Fu, Yanfang
    Liu, Liangxin
    APPLIED SCIENCES-BASEL, 2022, 12 (24):
  • [6] Security Analysis and Validation for Access Control in Multi-domain Environment Based on Risk
    Tang, Zhuo
    Zhang, Shaohua
    Li, Kenli
    Feng, Benming
    INFORMATION SECURITY PRACTICE AND EXPERIENCE, PROCEEDINGS, 2010, 6047 : 201 - 216
  • [7] A Dynamic Multi-domain Access Control Model in Cloud Computing
    Xiong, Dapeng
    Zou, Peng
    Cai, Jun
    He, Jun
    SECURITY IN COMPUTING AND COMMUNICATIONS (SSCC 2015), 2015, 536 : 3 - 12
  • [8] Fused access control mechanism based on usage control in multi-domain environment
    Yang, Zan
    Wang, Jian-Xin
    Yang, Lin
    Liu, Xiao-Ming
    Wei, Zhen-Zhen
    Chen, Jie-Kun
    Jilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition), 2014, 44 (01): : 158 - 163
  • [9] A New Hybrid Access Control Model for Multi-domain Systems
    Hasiba, Ben Attia
    Kahloul, Laid
    Benharzallah, Saber
    2017 4TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT), 2017, : 766 - 771
  • [10] A Multi-Domain Access Control Infrastructure Based on Diameter and EAP
    Ben Ayed, Souheil
    Teraoka, Fumio
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2012, E95D (02) : 503 - 513