ISCAS OpenIR  > 基础软件国家工程研究中心
separation of duty in trust-based collaboration
Deng Lingli; He Yeping; Xu Ziyao
2009
Conference Name4th International Conference on Information Security and Cryptology (Inscript 2008)
SourceLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Pages370-388
Conference DateDEC 14-17,
Conference PlaceBeijing, PEOPLES R CHINA
Indexed Type其他
Publish PlaceHEIDELBERGER PLATZ 3, D-14197 BERLIN, GERMANY
PublisherINFORMATION SECURITY AND CRYPTOLOGY
ISSN0302-9743
ISBN978-3-642-01439-0
DepartmentDeng, Lingli; He, Yeping; Xu, Ziyao Chinese Acad Sci, Inst Software, Beijing 100190, Peoples R China.
English AbstractWhen domains employing heterogeneous RBAC policies collaborate by crossdomain role-role mappings, their local Separation of Duty constraints face the risk of breaching. We present the requirements for constraint-secure interoperation, to prohibit implicit authorizations that break constraints from other member domains, and propose a trust-based framework to ensure constraint-secure interoperation. The framework introduces cross-domain migration and remote assurance of constraints between mutually trusted domains to maximize interoperability, while ensuring separation of constraints between distrusted domains to minimize security risk. Specifically, we use a bitmap-based history-recording mechanism for member domains to analyze the interplay among innerdomain role hierarchies, crossdomain mappings and constraints. Algorithms of a fully distributed implementation, security proofs and illustrative usage cases for the proposed solution are provided.
KeywordSecure Collaboration
SponsorshipChinese Assoc Cryptol Res, State Key Lab Informat Secur, Inst Software, Grad Univ Chinese Acad Sci, Natl Nat Sci Fdn China
Language英语
Content Type会议论文
URIhttp://ir.iscas.ac.cn/handle/311060/8366
Collection基础软件国家工程研究中心
Recommended Citation
GB/T 7714
Deng Lingli,He Yeping,Xu Ziyao. separation of duty in trust-based collaboration[C]. HEIDELBERGER PLATZ 3, D-14197 BERLIN, GERMANY:INFORMATION SECURITY AND CRYPTOLOGY,2009:370-388.
Files in This Item:
File Name/Size DocType Version Access License
separation of duty i(401KB) 开放获取--Application Full Text
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Deng Lingli]'s Articles
[He Yeping]'s Articles
[Xu Ziyao]'s Articles
Baidu academic
Similar articles in Baidu academic
[Deng Lingli]'s Articles
[He Yeping]'s Articles
[Xu Ziyao]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Deng Lingli]'s Articles
[He Yeping]'s Articles
[Xu Ziyao]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.