An attribute-based-delegation-model

  • Authors:
  • Chunxiao Ye;Yunqing Fu;Zhongfu Wu

  • Affiliations:
  • Chongqing University, Chongqing, China;Chongqing University, Chongqing, China;Chongqing University, Chongqing, China

  • Venue:
  • InfoSecu '04 Proceedings of the 3rd international conference on Information security
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

Delegation constraint of current delegation models is mostly delegation prerequisite conditions. In these models, delegation security fully depends on delegator and security administrator. In many cases, we need a more secured delegation with a strict constraint. This paper proposes an Attribute-Based-Delegation-Model (ABDM) with an extended delegation constraint. The delegation constraint in ABDM includes delegation attribute expression (DAE) and delegation prerequisite conditions. In ABDM, delegatee must satisfy delegation constraint (especially DAE) when assigned to a delegation role. With this delegation constraint, delegator can restrict the candidate of delegatee more strictly. ABDM relieves the security management effort of delegator and security administrator in delegation. ABDM also supports two new types of delegations: decided-delegatee and undecided-delegatee.