A usage-based authorization framework for collaborative computing systems

A usage-based authorization framework for collaborative computing systems
复制标题

DOI:
10.1145/1133058.1133084
复制
发表时间:
2006-06
期刊:
--
影响因子:
--
通讯作者:
Xinwen Zhang;Masayuki Nakae;M. Covington;R. Sandhu
Xinwen Zhang;Masayuki Nakae;M. Covington;R. Sandhu
中科院分区:
其他
文献类型:
--
作者:
Xinwen Zhang;Masayuki Nakae;M. Covington;R. Sandhu

文献摘要

被引文献

相似文献

网格等协作系统提供对分布式计算能力的高效和可扩展访问,并支持用户和平台之间的无缝资源共享。这种资源的异质分布以及用户、虚拟组织和资源提供商之间存在的各种协作模式需要可扩展、灵活和细粒度的访问控制,以保护单独和共享的计算资源。提出了一种基于使用控制(UCON)的协同应用授权框架。在我们的框架中,使用控制策略是使用主体和客体属性以及系统属性作为条件来定义的。通用属性不仅包括角色和组成员身份等持久属性,还包括主体和客体的可变使用属性。UCON中的条件可用于在临时协作中支持基于上下文的授权。作为概念验证,我们基于我们提出的体系结构实现了一个原型系统,并进行了实验研究,以证明我们方法的可行性和性能。
Collaborative systems such as Grids provide efficient and scalable access to distributed computing capabilities and enable seamless resource sharing between users and platforms. This heterogeneous distribution of resources and the various modes of collaborations that exist between users, virtual organizations, and resource providers require scalable, flexible, and fine-grained access control to pro-tect both individual and shared computing resources. In this paper we propose a usage control (UCON) based authorization frame-work for collaborative applications. In our framework, usage con-trol policies are defined using subject and object attributes, along with system attributes as conditions. General attributes include not only persistent attributes such as role and group memberships, but also mutable usage attributes of subjects and objects. Conditions in UCON can be used to support context-based authorizations in ad-hoc collaborations. As a proof-of-concept we implement a pro-totype system based on our proposed architecture and conduct ex-perimental studies to demonstrate the feasibility and performance of our approach.