首页 | 本学科首页   官方微博 | 高级检索  
     


An extended attribute based access control model with trust and privacy: Application to a collaborative crisis management system
Affiliation:1. Center for Security, Theory and Algorithmic Research, International Institute of Information Technology, Hyderabad, Gachibowli, Hyderabad, 500032, Telangana, India;2. Center for Security, Theory and Algorithmic Research, International Institute of Information Technology, Hyderabad, Gachibowli, Hyderabad, 500032, Telangana, India;3. College of Computer Science and Technology, China University of Petroleum (East China), Qingdao 266555, China;4. Instituto de Telecomunicações, Covilhã, 6201-001, Portugal;1. Electronic and Computer Science Department, University of Southampton, University road, Southampton, Hampshire SO17 1BJ, United Kingdom;2. Computer Science and Engineering Department, Faculty of Electronic Engineering, Menoufia University, Menoufia, Egypt
Abstract:Many efforts in the area of computer security have been drawn to attribute-based access control (ABAC). Compared to other adopted models, ABAC provides more granularity, scalability, and flexibility. This makes it a valuable access control system candidate for securing platforms and environments used for coordination and cooperation among organizations and communities, especially over open networks such as the Internet. On the other hand, the basic ABAC model lacks provisions for context, trust and privacy issues, all of which are becoming increasingly critical, particularly in high performance distributed collaboration environments. This paper presents an extended access control model based on attributes associated with objects and subjects. It incorporates trust and privacy issues in order to make access control decisions sensitive to the cross-organizational collaboration context. Several aspects of the proposed model are implemented and illustrated by a case study that shows realistic ABAC policies in the domain of distributed multiple organizations crisis management systems. Furthermore, the paper shows a collaborative graphical tool that enables the actors in the emergency management system to make better decisions. The prototype shows how it guarantees the privacy of object’s attributes, taking into account the trust of the subjects. This tool incorporates a decision engine that relies on attribute based policies and dynamic trust and privacy evaluation. The resulting platform demonstrates the integration of the ABAC model, the evolving context, and the attributes of actors and resources.
Keywords:Access control  ABAC  Trust  Privacy  Context  Distributed collaboration  Crisis management system
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号