A policy framework for access management in federated information sharing

被引:0
|
作者
Bhatti, R [1 ]
Bertino, E [1 ]
Ghafoor, A [1 ]
机构
[1] Purdue Univ, Sch Elect & Comp Engn, W Lafayette, IN 47907 USA
来源
Security Management, Integrity, and Internal Control in Information Systems | 2005年 / 193卷
关键词
federated systems; policy-based management; XML access control;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Current mechanisms for distributed access management are limited in their capabilities to provide federated information sharing while ensuring adequate levels of resource protection. This work presents a policy-based framework designed to address these limitations for access management in federated systems. In particular, it supports: (i) decentralized administration while preserving local autonomy, (ii) fine-grained access control while avoiding rule-explosion in the policy,(iii) credential federation through the use of interoperable protocols, with support for single sign on for federated users, (iv) specification and enforcement of semantic and contextual constraints to support integrity requirements and contractual obligations, and (v) usage control in resource provisioning through effective session management. The paper highlights the significance of our policy-based approach in comparison with related mechanisms. It also presents a system architecture of our implementation prototype.
引用
收藏
页码:95 / 120
页数:26
相关论文
共 50 条
  • [1] A Policy Framework for Access Management in Federated Information Sharing
    Bhatti, Rafae
    Bertino, Elisa
    Ghafoor, Arif
    IFIP Advances in Information and Communication Technology, 2005, 193 : 95 - 120
  • [2] X-FEDERATE: A policy engineering framework for federated access management
    Bhatti, Rafae
    Bertino, Elisa
    Ghafoor, Arif
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2006, 32 (05) : 330 - 346
  • [3] Federated Access to Heterogeneous Information Resources in the Neuroscience Information Framework (NIF)
    Gupta, Amarnath
    Bug, William
    Marenco, Luis
    Qian, Xufei
    Condit, Christopher
    Rangarajan, Arun
    Mueller, Hans Michael
    Miller, Perry L.
    Sanders, Brian
    Grethe, Jeffrey S.
    Astakhov, Vadim
    Shepherd, Gordon
    Sternberg, Paul W.
    Martone, Maryann E.
    NEUROINFORMATICS, 2008, 6 (03) : 205 - 217
  • [4] Federated Access to Heterogeneous Information Resources in the Neuroscience Information Framework (NIF)
    Amarnath Gupta
    William Bug
    Luis Marenco
    Xufei Qian
    Christopher Condit
    Arun Rangarajan
    Hans Michael Müller
    Perry L. Miller
    Brian Sanders
    Jeffrey S. Grethe
    Vadim Astakhov
    Gordon Shepherd
    Paul W. Sternberg
    Maryann E. Martone
    Neuroinformatics, 2008, 6 : 205 - 217
  • [5] A framework for access control and management in dynamic cooperative and federated environments
    Ibrohimovna, Malohat
    de Groot, Sonia Heemstra
    AICT: 2009 FIFTH ADVANCED INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS, 2009, : 459 - 466
  • [6] An adaptive access control policy management framework
    Tout, H
    ISWS '05: Proceedings of the 2005 International Symposium on Web Services and Applications, 2005, : 10 - 15
  • [7] Ubiquitous Personal Study: a framework for supporting information access and sharing
    Chen, Hong
    Jin, Qun
    PERSONAL AND UBIQUITOUS COMPUTING, 2009, 13 (07) : 539 - 548
  • [8] Ubiquitous Personal Study: a framework for supporting information access and sharing
    Hong Chen
    Qun Jin
    Personal and Ubiquitous Computing, 2009, 13 : 539 - 548
  • [9] Dynamic policy management framework for partial policy information
    Yu, CM
    Ng, KW
    ADVANCES IN GRID COMPUTING - EGC 2005, 2005, 3470 : 578 - 588
  • [10] SHARE: Secure information sHaring frAmework for emeRgency managemEnt
    Carminati, Barbara
    Ferrari, Elena
    Guglielmi, Michele
    2013 IEEE 29TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE), 2013, : 1336 - 1339