首页> 外文会议>International Conference on Advanced Communications and Computation >Trans-Organizational Role-Based Access Control in Android: Secure Mechanism for Verifying User-Role Assignments of Organizations
【24h】

Trans-Organizational Role-Based Access Control in Android: Secure Mechanism for Verifying User-Role Assignments of Organizations

机译:基于跨组织的角色的访问控制在Android中:用于验证组织的用户角色分配的安全机制

获取原文

摘要

The role-based access control (RBAC) is a natural and versatile model of the access control principle. In the real world, it is common that an organization provides a service to a user who owns a certain role that was issued by a different organization. However, such a trans-organizational RBAC is not common in a computer network because it is difficult to establish both the security that prohibits malicious impersonation of roles and the flexibility that allows small organizations/individual users to fully control their own roles. To solve this problem, this study proposes a mechanism that makes use of the hierarchical ID-based encryption scheme and the challenge-response authentication protocol. The proposed mechanism contributes to achieve both the security and the flexibility and it provides additional features that are common in physical communication but are not obvious in the cyberworld. This study also reports a prototyping system that is implemented on Android-enabled mobile devices. The proposed system employs the needed cryptographic mechanisms, and new technologies, namely, near-field communication and two-dimensional codes, are employed to realize locally closed communication between devices.
机译:基于角色的访问控制(RBAC)是访问控制原理的自然和多功能模型。在现实世界中,常见的是,组织为拥有由不同组织发出的某个角色的用户提供服务。然而,这种跨组织的RBAC在计算机网络中并不常见,因为很难建立禁止恶意冒充角色的安全性以及允许小型组织/个人用户完全控制自己角色的灵活性的安全性。为了解决这个问题,本研究提出了一种机制,该机制利用基于分层ID的加密方案和挑战 - 响应认证协议。拟议的机制有助于实现安全性和灵活性,并且提供了在物理通信中常见的额外功能,但在Cyber​​world中并不明显。本研究还报告了一种原型系统,该系统在启用了Android的移动设备上实现。所提出的系统采用所需的加密机制,以及新技术,即近场通信和二维代码,用于实现设备之间的局部封闭通信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号