|
ABSTRACT
Delegation is the process whereby an active entity in a distributed environment authorizes another entity to access resources. In today's distributed systems, a user often needs to act on another user's behalf with some subset of his/her rights. Most systems have attempted to resolve such delegation requirements with ad-hoc mechanisms by compromising existing disorganized policies or simply attaching additional components to their applications. Still, there is a strong need in the large, distributed systems for a mechanism that provides effective privilege delegation and revocation management. This paper describes a rule-based framework for role-based delegation and revocation. The basic idea behind a role-based delegation is that users themselves may delegate role authorities to others to carry out some functions authorized to the former. We present a role-based delegation model called RDM2000 (role-based delegation model 2000) supporting hierarchical roles and multistep delegation. Different approaches for delegation and revocation are explored. A rule-based language for specifying and enforcing policies on RDM2000 is proposed. We describe a proof-of-concept prototype implementation of RDM2000 to demonstrate the feasibility of the proposed framework and provide secure protocols for managing delegations. The prototype is a web-based application for law enforcement agencies allowing reliable delegation and revocation. The future directions are also discussed.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
 |
2
|
|
 |
3
|
|
| |
4
|
|
| |
5
|
|
| |
6
|
Barka, E. and Sandhu, R. 2000. Framework for role-based delegation model. In Proceedings of 23rd National Information Systems Security Conference, Baltimore, October 16--19, 2000b, 101--114.
|
| |
7
|
Bhamidipati, V. and Sandhu, R. 2000. Push Architectures for USER ROLE assignment. In Proceedings of 23rd National Information Systems Security Conference, Baltimore, October 16--19, 2000, 89--100.
|
| |
8
|
|
| |
9
|
|
| |
10
|
Ellison, C., Frantz, B., Lampson, B., Rivest, R., Thomas, B., and Ylonen, T. 1999. SPKI Certificate Theory, RFC2693, http://www.ietf.org/rfc/rfc2693.txt, 1999.
|
 |
11
|
|
| |
12
|
Ferraiolo, D., Cugini, J., and Kuhn, D. R. 1995. Role-based access control (RBAC): features and Motivations. In Proceedings of 11th Annual Computer Security Application Conference. New Orleans, LA, December 11--15 1995, 241--241.
|
| |
13
|
|
| |
14
|
|
| |
15
|
Gasser, M. and McDermott, E. 1990. An architecture for practical delegation a distributed system. IEEE Computer Society Symposium on Research in Security and Privacy. Oakland, CA, May 7--9, 1990.
|
 |
16
|
|
| |
17
|
|
| |
18
|
Hayton, R., Bacon, J., and Moody, K. 1998. OASIS: access control in an open, distributed environment. In Proceedings of 1998 IEEE Symposium on Security and Privacy. Oakland, CA, May 3--6. IEEE Computer Society Press, Los Alamitos, CA, 3--14.
|
| |
19
|
|
 |
20
|
|
| |
21
|
|
| |
22
|
|
| |
23
|
Liebrand, M., Ellis, H. J., Phillips, C., and Ting, T. C. 2002. Role delegation for a distributed, unified RBAC/MAC. In Proceedings of Sixteenth Annual IFIP WG 11.3 Working Conference on Data and Application Security King's College, University of Cambridge, UK July 29--31, 2002.
|
 |
24
|
|
| |
25
|
McNamara, C. 1997. Basics of delegating. http://www.mapnp.org/library/guiding/delegate/basics.htm.
|
 |
26
|
|
 |
27
|
|
| |
28
|
|
| |
29
|
Wielemaker, J. SWI-Prolog. http://www.swi.psy.uva.nl/projects/SWI-Prolog/
|
 |
30
|
|
 |
31
|
|
 |
32
|
|
CITED BY 16
|
|
|
|
|
Joon S. Park , Keith P. Costello , Teresa M. Neven , Josh A. Diosomito, A composite rbac approach for large, complex organizations, Proceedings of the ninth ACM symposium on Access control models and technologies, June 02-04, 2004, Yorktown Heights, New York, USA
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Tsung-Yi Chen , Yuh-Min Chen , Hui-Chuan Chu , Chin-Bin Wang, Development of an access control model, system architecture and approaches for resource sharing in virtual enterprise, Computers in Industry, v.58 n.1, p.57-73, January, 2007
|
|
|
Quan Pham , Jason Reid , Adrian McCullagh , Ed Dawson, Commitment issues in delegation process, Proceedings of the sixth Australasian conference on Information security, January 01-01, 2008, Wollongong, NSW, Australia
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|