Implementing role based access control for federated information systems on the web

  • Authors:
  • Kerry Taylor;James Murty

  • Affiliations:
  • CSIRO Mathematical and Information Sciences, and CRC for Enterprise Distributed Systems Technology, GPO Box 664, Canberra, ACT;CSIRO Mathematical and Information Sciences, and CRC for Enterprise Distributed Systems Technology, GPO Box 664, Canberra, ACT

  • Venue:
  • ACSW Frontiers '03 Proceedings of the Australasian information security workshop conference on ACSW frontiers 2003 - Volume 21
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

There is rapidly increasing interest in Australia in on-line sharing of information stored in corporate databases, especially within and between staff of independent government agencies. Biological collections databases and population health GIS are good examples of the frequent situation where database custodians are looking for dynamic, distributed, heterogenous federated information system models for information sharing within loosely constituted communities. This paper describes a security model for authentication and access control to federated systems. The model supports single sign-on for users; a high level of autonomy for database custodians; and a low maintenance overhead. The model's implementation using PKI and Web technology is described.