lightweight decentralized authorization model for inter-domain collaborations

  • Authors:
  • Hannah K. Lee;Heiko Luedemann

  • Affiliations:
  • University Hamburg, Hamburg, Germany;University Hamburg, Hamburg, Germany

  • Venue:
  • Proceedings of the 2007 ACM workshop on Secure web services
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Inter-domain collaborations comprise of a series of tasks, whose run-time environment stretches over heterogeneous systems governed by different set of policies and where participating organizations desire to preserve control over their resources. One of the major security challenges in modeling those inter-domain collaborations is providing a decentralized authorization solution. At the core of this challenge lie two problems: 1) an authorization decision maker does not know who a principal is and 2) which set of privileges this principal owns if the principal is originated from outside of the decision maker's domain. Currently, a number of different approaches tackle this problem and claim to provide a full-fledged solution. These approaches, however, often require particular use of infrastructures and their own policy languages. In this paper, we propose a lightweight model using the concept of distributed roles from the dRBAC model to bridge different domain boundaries. Based on e-Government collaboration scenarios, we identify a set of requirements of decentralized authorization and propose an extension to the current XACML specification as a realization of our model.