首页> 外文会议>ACM workshop on Secure web services >Role-based access control for data service integration
【24h】

Role-based access control for data service integration

机译:基于角色的访问控制,用于数据服务集成

获取原文

摘要

We describe the implementation of role-based access control in a data service integration system. Users in research or other projects may access a diverse collection of data sources but are to allowed access to only the part of the data collection that is necessary for their purposes. To simplify the administration of the access control, Role Based Access control is used, with the role hierarchy defined within and limited to each project. User queries to the integration system are analysed for their data access needs and those needs checked against the access control policies. The policies for the data held by individual data custodians can be managed and implemented by the custodian, or held in a central authorisation server in the integration system. The system is built around the Security Assertion Markup Language and eXtensible Access Control Markup Language standards. The access control architecture was developed for a health data integration system, but both the architecture and some of itscomponents for authentication and authorisation could be readily reused in other similar systems.
机译:我们描述了数据服务集成系统中基于角色的访问控制的实现。研究或其他项目中的用户可以访问各种数据源集合,但只能访问其目的所需的部分数据集合。为了简化访问控制的管理,使用了基于角色的访问控制,其中角色层次结构定义在每个项目中,并且仅限于每个项目。分析对集成系统的用户查询的数据访问需求,并根据访问控制策略检查这些需求。由单个数据保管人保存的数据策略可以由保管人管理和实施,也可以保存在集成系统中的中央授权服务器中。该系统基于安全性断言标记语言和可扩展访问控制标记语言标准构建。访问控制体系结构是为健康数据集成系统开发的,但是该体系结构及其某些用于身份验证和授权的组件可以很容易地在其他类似系统中重用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号