Consistency checking of role assignments in inter-organizational collaboration

  • Authors:
  • Paul El Khoury;Emmanuel Coquery;Mohand-Said Hacid

  • Affiliations:
  • University Claude Bernard Lyon, LIRIS CNRS, Mougins - France;University Claude Bernard Lyon, LIRIS CNRS, Villeurbanne Cedex - France;University Claude Bernard Lyon, LIRIS CNRS, Villeurbanne Cedex - France

  • Venue:
  • SPRINGL '08 Proceedings of the SIGSPATIAL ACM GIS 2008 International Workshop on Security and Privacy in GIS and LBS
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The establishment of globalization is driving inter- organizational collaboration towards a necessity. We cannot expect total conformity between organizations nor homogeneous security settings. Nevertheless, each organization, with its own security policies, needs to exchange data. Employees involved in inter-organizational tasks shall require remote access to data hosted by other organizations. Administrating access control policies for those employees creates problems for security officers, particularly for role assignments. Flexibility in extending (or restricting) permissions for roles imported from other organizations is required. In this work, we present an approach based on Description Logic formalisms to create from the inter-organizational agreement a set of bridge rules that in addition to (i) the permissions assigned to a given role from one organization and (ii) the permissions assigned to another role in the other organization, allows security officers to check consistency of the resulting combination of roles from both organizations.