School of Computing

Achieving Fine-grained Access Control in Virtual Organisations

N. Zhang, L. Yao, A. Nenadic, J. Chin, C. Goble, A. Rector, D. Chadwick, S. Otenko, and Q. Shi

Concurrency and Computation: Practice and Experience, 19(9):182-196, June 2007 Available from http://www3.interscience.wiley.com/cgi-bin/fulltext/113392827/PDFSTART.

Abstract

In a virtual organization environment, where services and data are provided and shared amongorganizations from different administrative domains and protected with dissimilar security policies and measures, there is a need for a flexible authentication framework that supports the use of various authentication methods and tokens. The authentication strengths derived from the authentication methods and tokens should be incorporated into an access-control decision-making process, so that more sensitive resources are available only to users authenticated with stronger methods. This paper reports our ongoingefforts in designing and implementing such a framework to facilitate multi-level and multi-factor adaptive authentication and authentication strength linked fine-grained access control. The proof-ofconcept prototype is designed and implemented in the Shibboleth and PERMIS infrastructures, which specifies protocols to federate authentication and authorization information and provides a policy-driven, role-based, access- control decision-making capability.

Download publication 587 kbytes (PDF)

Bibtex Record

@article{2413,
author = {N. Zhang and L. Yao and A. Nenadic and J. Chin and C. Goble and A. Rector and D. Chadwick and S. Otenko and Q. Shi},
title = {Achieving {F}ine-grained {A}ccess {C}ontrol in {V}irtual {O}rganisations},
month = {June},
year = {2007},
pages = {182-196},
keywords = {determinacy analysis, Craig interpolants},
note = {Available from http://www3.interscience.wiley.com/cgi-bin/fulltext/113392827/PDFSTART},
doi = {},
url = {http://www.cs.kent.ac.uk/pubs/2007/2413},
    publication_type = {article},
    submission_id = {10361_1155647055},
    ISSN = {1532-0626},
    journal = {Concurrency and Computation: Practice and Experience},
    publisher = {John Wiley and Sons},
    volume = {19},
    number = {9},
}

School of Computing, University of Kent, Canterbury, Kent, CT2 7NF

Enquiries: +44 (0)1227 824180 or contact us.

Last Updated: 21/03/2014