| Using trust and risk in role-based access control policies |
| Full text |
Pdf
(222 KB)
|
| Source
|
Symposium on Access Control Models and Technologies
archive
Proceedings of the ninth ACM symposium on Access control models and technologies
table of contents
Yorktown Heights, New York, USA
SESSION: Access management for distributed systems
table of contents
Pages: 156 - 162
Year of Publication: 2004
ISBN:1-58113-872-5
|
|
Authors
|
|
Nathan Dimmock
|
University of Cambridge, Cambridge, UK
|
|
András Belokosztolszki
|
University of Cambridge, Cambridge, UK
|
|
David Eyers
|
University of Cambridge, Cambridge, UK
|
|
Jean Bacon
|
University of Cambridge, Cambridge, UK
|
|
Ken Moody
|
University of Cambridge, Cambridge, UK
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 17, Downloads (12 Months): 180, Citation Count: 0
|
|
|
ABSTRACT
Emerging trust and risk management systems provide a framework for principals to determine whether they will exchange resources, without requiring a complete definition of their credentials and intentions. Most distributed access control architectures have far more rigid policy rules, yet in many respects aim to solve a similar problem. This paper elucidates the similarities between trust management and distributed access control systems by demonstrating how the OASIS access control system and its rôle-based policy language can be extended to make decisions on the basis of trust and risk analyses rather than on the basis of credentials alone. We apply our new model to the prototypical example of a file storage and publication service for the Grid, and test it using our Prolog-based OASIS implementation.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
 |
2
|
|
| |
3
|
Ashton Applewhite. Getting the Grid. IEEE Distributed Systems Online, May 2002.
|
| |
4
|
|
 |
5
|
|
| |
6
|
|
| |
7
|
Marco Carbone, Mogens Nielsen, and Vladimiro Sassone. A formal model for trust in dynamic networks. Research Series RS-03-04, BRICS, Department of Computer Science, University of Aarhus, January 2003. EU Project SECURE IST-2001-32486 Deliverable 1.1.
|
| |
8
|
|
| |
9
|
Tyrone Grandison and Morris Sloman. A survey of trust in internet applications. IEEE Communications Society, Surveys and Tutorials, 3(4), 2000.
|
| |
10
|
ISO/IEC JTC1/SC22 Working Group. ISO/IEC 9899 - Programming languages - C, 1999.
|
| |
11
|
|
| |
12
|
Audun Jøsang, Elizabeth Gray, and Michael Kinateder. Analysing topologies of transitive trust. In Proceedings of the Workshop of Formal Aspects of Security and Trust (FAST), September 2003.
|
| |
13
|
|
| |
14
|
|
| |
15
|
Jean-Marc Seigneur, Stephen Farrell, Christian Damsgaard Jensen, Elizabeth Gray, and Chen Yong. End-to-end trust in pervasive computing starts with recognition. In Proceedings of the First International Conference on Security in Pervasive Computing, 2003.
|
| |
16
|
Li Xiong and Ling Liu. Building trust in decentralized peer-to-peer electronic communities. In The 5th International Conference on Electronic Commerce Research, October 2002.
|
| |
17
|
Walt Teh-Ming Yao. Fidelis: A policy-driven trust management framework. In Proc. of the 1st Intern'l Conf. on Trust Management, number 2692 in LNCS. Springer-Verlag, May 2003.
|
 |
18
|
|
| |
19
|
|
CITED BY 14
|
|
|
|
|
|
|
|
|
|
|
Audun Jøsang , Dieter Gollmann , Richard Au, A method for access authorisation through delegation networks, Proceedings of the 2006 Australasian workshops on Grid computing and e-research, p.165-174, January 16-19, 2006, Hobart, Tasmania, Australia
|
|
|
|
|
|
Tsung-Yi Chen , Yuh-Min Chen , Chin-Bin Wang , Hui-Chuan Chu , Huimei Yang, Secure resource sharing on cross-organization collaboration using a novel trust method, Robotics and Computer-Integrated Manufacturing, v.23 n.4, p.421-435, August, 2007
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|