...
首页> 外文期刊>Information security journal >A Role Engineering Framework to Support Dynamic Authorizations in Collaborative Environments
【24h】

A Role Engineering Framework to Support Dynamic Authorizations in Collaborative Environments

机译:一个在协作环境中支持动态授权的角色工程框架

获取原文
获取原文并翻译 | 示例
           

摘要

With the increasing availability of networks and the advancements in their underlying infrastructure of mobile devices, access control and authorization issues will be enablers of future technologies in collaborative environments. Recent works demonstrate efforts to dynamically authorize users without prior knowledge and with no security configuration attributes or roles previously assigned to them. Moreover, current role-based engineering approaches construct role hierarchies without reflecting the organizational structure, since they do not take into account structural organizational characteristics. In this paper we propose an innovative role structure, not solely dependent on naming methods but also that takes into account organizational as well as functional characteristics to provide a practical role assignment methodology between organizations in a collaborative environment. More specifically, we argue that beyond the fact that a role represents a job assignment to perform certain function(s), it is also a composite element representing several organizational characteristics such as organizational function, organizational domain and level of authority. The proposed role structure enables role-to-role assignment as external nonlocal users request access in a particular information system (e.g., people on the move, users logged in from a collaborative organization) and acquire local role(s). A clear advantage in the proposed framework is its flexibility in the role assignment process, since the proposed role decomposition does not require an exact match of predefined credentials. The methodology is autonomous, as no prior trust establishment is required between interactive organizations, expendable as new organizations can join the collaboration without affecting the existing ones, flexible as it does not affect the local access control policy, scalable as the collaboration can increase arbitrary and efficient as the comparison methodology guarantees the selection of the appropriate local role, if such one exists.
机译:随着网络可用性的提高以及其在移动设备的基础结构中的进步,访问控制和授权问题将成为协作环境中未来技术的促成因素。最近的工作证明了在没有先验知识并且没有安全配置属性或以前分配给他们的角色的情况下动态授权用户的努力。而且,当前基于角色的工程方法在不反映组织结构的情况下构造了角色层次结构,因为它们没有考虑结构性组织特征。在本文中,我们提出了一种创新的角色结构,该结构不仅依赖于命名方法,而且还考虑了组织以及功能特征,以在协作环境中提供组织之间的实用角色分配方法。更具体地说,我们认为,除了角色代表执行某些功能的工作分配这一事实外,它还是代表多个组织特征(例如组织职能,组织领域和权限级别)的复合元素。当外部非本地用户请求访问特定信息系统(例如,在途人员,从协作组织登录的用户)并获取本地角色时,建议的角色结构可实现角色到角色的分配。提议的框架的明显优势是它在角色分配过程中的灵活性,因为提议的角色分解不需要预定义凭据的精确匹配。该方法是自主的,因为在交互式组织之间不需要事先建立信任;由于新组织可以在不影响现有组织的情况下加入协作,因此是可扩展的;由于不影响本地访问控制策略而具有灵活性;由于协作可以增加任意性和可扩展性,因此该方法可扩展这种比较有效,因为比较方法可以确保选择适当的本地角色(如果存在)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号