Federated Authorization for Managed Data Sharing: Experiences from the ImPACT Project

Federated Authorization for Managed Data Sharing: Experiences from the ImPACT Project
复制标题

托管数据共享的联合授权:ImPACT 项目的经验

DOI:
--
复制
发表时间:
2021
期刊:
International Conference on Computer Communications and Networks
影响因子:
--
通讯作者:
I. Baldin
I. Baldin
中科院分区:
--
文献类型:
--
作者:
J. Chase;I. Baldin

文献摘要

被引文献

相似文献

本文介绍了Impact信任平面的基本原理和设计,Impact是一个管理共享受限数据的联邦平台。该体系结构的关键元素包括:基于Web的公证人,用于基于数据使用协议的声明模板建立凭证;联合授权管道;集成流行的身份管理服务;以及基于逻辑信任模型和链接证书存储库的可编程策略。我们展示了信任平面的这些元素是如何协同工作的,并将这些想法与联合授权原则放在一起。本文的一个重点和贡献是探索由此产生的体系结构的局限性和相互竞争的设计目标之间的紧张关系。我们还指出了未来扩展的方向,包括从云托管的数据飞地进行策略检查的数据访问,增强了对数据泄露和外泄的防御。
This paper presents the rationale and design of the trust plane for ImPACT, a federated platform for managed sharing of restricted data. Key elements of the architecture include Web-based notaries for credential establishment based on declarative templates for Data Usage Agreements, a federated authorization pipeline, integration of popular services for identity management, and programmable policy based on a logical trust model with a repository of linked certificates. We show how these elements of the trust plane work in concert, and set the ideas in context with principles of federated authorization. A focus and contribution of the paper is to explore limitations of the resulting architecture and tensions among competing design goals. We also point the way toward future extensions, including policy-checked data access from cloud-hosted data enclaves with enhanced defenses against data leakage and exfiltration.