| Modular authorization |
| Full text |
Pdf
(223 KB)
|
| Source
|
ACM Workshop on Role Based Access Control
archive
Proceedings of the sixth ACM symposium on Access control models and technologies
table of contents
Chantilly, Virginia, United States
Pages: 97 - 105
Year of Publication: 2001
ISBN:1-58113-350-2
|
|
Authors
|
|
| Sponsor |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 2, Downloads (12 Months): 19, Citation Count: 4
|
|
|
ABSTRACT
There are three major drawbacks of a centralized security administration in distributed systems: It creates a bottleneck for request handling, it tends to enforce homogeneous security structures in heterogeneous user groups and organizations, and it is a weak point in terms of security attacks, reliability, and fault tolerance. In this paper we introduce a distributed authorization concept which is based on a modular authorization language for supporting cooperatingdistributed authorization teams. These teams are partially ordered into a hierarchy in that they inherit authorization rules from higher order teams but still exercise their autonomy by (dynamically) setting local rules that serve the special local needs in distributed organizations.Conflictsbetween between rules inherited from different higher ranking sources, orviolationsof higher order rules through local rules would be detected, on the logical level or through request evaluation, as contradictions or contradicting results, respectively. Conflict resolution mechanisms are presented, and examples are discussed extensively.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
 |
2
|
|
 |
3
|
|
| |
4
|
|
 |
5
|
Sushil Jajodia , Pierangela Samarati , V. S. Subrahmanian , Eliza Bertino, A unified framework for enforcing multiple access control policies, Proceedings of the 1997 ACM SIGMOD international conference on Management of data, p.474-485, May 11-15, 1997, Tucson, Arizona, United States
|
| |
6
|
|
 |
7
|
|
 |
8
|
|
| |
9
|
H. F. Wedde, B. Korel, S. Chen, D. C. Daniels, S. Nagaraj, and B. Santhanam. Transparent Access to Large Files That Are Stored across Sites. In Readings in Distributed Computing Systems Theory. IEEE Computer Society Press, 1994.
|
| |
10
|
H. F. Wedde and M. Lischka. New Dimensions in Distributed Journalism Through Dragon Slayer III. In Proc. of the 7th Euromicro Workshop on Parallel and Distributed Processing, Madeira, Portugal, Feb 1999. Euromicro, IEEE Computer Society Press.
|
| |
11
|
H. F. Wedde and J.-O. Siepmann. A Universal Framework for Managing Metadata in the Distributed Dragon Slayer System. In Euromicro Workshop on Multimedia and Telecommunications. Euromicro, IEEE Computer Society Press, Sept. 2000.
|
INDEX TERMS
Primary Classification:
D.
Software
D.4
OPERATING SYSTEMS
Additional Classification:
K.
Computing Milieux
K.6
MANAGEMENT OF COMPUTING AND INFORMATION SYSTEMS
General Terms:
Design,
Management,
Performance,
Reliability,
Security,
Theory
Keywords:
authorization,
composability,
conflicts,
modularity,
role-based access control,
violations
|