Achieving Fine-Grained Access Control In Virtual Organizations

CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE(2007)

引用 15|浏览22
暂无评分
摘要
In a virtual organization environment, where services and data are provided and shared among organizations from different administrative domains and protected with dissimilar security policies and measures, there is a need for a flexible authentication framework that supports the use of various authentication methods and tokens. The authentication strengths derived from the authentication methods and tokens should be incorporated into an access-control decision-making process, so that more sensitive resources are available only to users authenticated with stronger methods. This paper reports our ongoing efforts in designing and implementing such a framework to facilitate multi-level and multi-factor adaptive authentication and authentication strength linked fine-grained access control. The proof-of-concept prototype is designed and implemented in the Shibboleth and PERMIS infrastructures, which specifies protocols to federate authentication and authorization information and provides a policy-driven, role-based, access-control decision-making capability. Copyright (c) 2006 John Wiley & Sons, Ltd.
更多
查看译文
关键词
authentication, authorization, virtual organization, Shibboleth, PERMIS, smart tokens
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要