首页> 外文会议>IEEE International Symposium on Policies for Distributed Systems and Networks >Towards Autonomous Administrations of Decentralized Authorization for Inter-domain Collaborations
【24h】

Towards Autonomous Administrations of Decentralized Authorization for Inter-domain Collaborations

机译:对域间协作的分散授权的自主主管部门

获取原文

摘要

Inter-domain collaborations are composed of a series of tasks, whose run-time environment stretches over heterogeneous systems governed by different sets of policies. Though the collaborators are willing to share resources and knowledge to reach a set of common goals, they often desire to preserve control over their resources and prevent internal information from unnecessary disclosure. Thus, one of the major challenges in modeling a security policy for the inter-domain collaborations is allowing autonomous administration of internal resources and principals. In this paper, we present a conceptional framework called interactive RBAC (iRBAC), which builds a RBAC system for such inter-domain collaborations with an additional intermediate layer called interactive Roles (iRoles). Providing transparent linkage between actors in collaborations and domain specific local principals, this extra indirection not only enables autonomous policy administrations on user-role and role-permission assignments, but it also assists local principals in collaborators’ domains to be mapped in alignment to functional roles derived from collaborative process definitions. Challenges in building a RBAC system above domain boundaries such as preserving consistency properties and avoiding “role explosion” during user-role assignment are also discussed.
机译:域间协作由一系列任务组成,其运行时环境延伸到由不同一组政策管理的异构系统。虽然合作者愿意分享资源和知识,但是他们常常希望保护对资源的控制,并防止不必要的披露中的内部信息。因此,为域间协作建模安全策略的主要挑战之一是允许自主管理内部资源和校长。在本文中,我们介绍了一个名为Interactive RBAC(IRBAC)的概念框架,其为这种域间协作的RBAC系统与称为交互式角色的额外中间层(iRoles)构建了这种域间协作。在合作和域特定于本地校长中提供透明的联系,这个额外的间接不仅可以实现关于用户角色和角色权限分配的自主政策主管,而且还可以帮助映射到功能角色的协作者域中的本地校长来自协作过程定义。还讨论了在用户角色分配期间构建域边界之类的RBAC系统的挑战,例如保留一致性属性并避免“角色爆炸”。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号