Title: | separation of duty in trust-based collaboration |
Author: | Deng Lingli
; He Yeping
; Xu Ziyao
|
Source: | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
|
Conference Name: | 4th International Conference on Information Security and Cryptology (Inscript 2008)
|
Conference Date: | DEC 14-17,
|
Issued Date: | 2009
|
Conference Place: | Beijing, PEOPLES R CHINA
|
Keyword: | Secure Collaboration
|
Publisher: | INFORMATION SECURITY AND CRYPTOLOGY
|
Publish Place: | HEIDELBERGER PLATZ 3, D-14197 BERLIN, GERMANY
|
Indexed Type: | 其他
|
ISSN: | 0302-9743
|
ISBN: | 978-3-642-01439-0
|
Department: | Deng, Lingli; He, Yeping; Xu, Ziyao Chinese Acad Sci, Inst Software, Beijing 100190, Peoples R China.
|
Sponsorship: | Chinese Assoc Cryptol Res, State Key Lab Informat Secur, Inst Software, Grad Univ Chinese Acad Sci, Natl Nat Sci Fdn China
|
English Abstract: | When domains employing heterogeneous RBAC policies collaborate by crossdomain role-role mappings, their local Separation of Duty constraints face the risk of breaching. We present the requirements for constraint-secure interoperation, to prohibit implicit authorizations that break constraints from other member domains, and propose a trust-based framework to ensure constraint-secure interoperation. The framework introduces cross-domain migration and remote assurance of constraints between mutually trusted domains to maximize interoperability, while ensuring separation of constraints between distrusted domains to minimize security risk. Specifically, we use a bitmap-based history-recording mechanism for member domains to analyze the interplay among innerdomain role hierarchies, crossdomain mappings and constraints. Algorithms of a fully distributed implementation, security proofs and illustrative usage cases for the proposed solution are provided. |
Language: | 英语
|
Content Type: | 会议论文
|
URI: | http://ir.iscas.ac.cn/handle/311060/8366
|
Appears in Collections: | 基础软件国家工程研究中心_会议论文
|
File Name/ File Size |
Content Type |
Version |
Access |
License |
|
separation of duty in trust-based collaboration.pdf(401KB) | -- | -- | 限制开放 | -- | 联系获取全文 |
|
Recommended Citation: |
Deng Lingli,He Yeping,Xu Ziyao. separation of duty in trust-based collaboration[C]. 见:4th International Conference on Information Security and Cryptology (Inscript 2008). Beijing, PEOPLES R CHINA. DEC 14-17,.
|
|
|