A usage-based authorization framework for collaborative computing systems

  • Authors:
  • Xinwen Zhang;Masayuki Nakae;Michael J. Covington;Ravi Sandhu

  • Affiliations:
  • George Mason University, Fairfax, Virginia;NEC Corporation, Kawasaki, Kanagawa, Japan;Intel Corporation, Hillsboro, Oregon;George Mason University and TriCipher Inc., USA

  • Venue:
  • Proceedings of the eleventh ACM symposium on Access control models and technologies
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Collaborative systems such as Grids provide efficient and scalable access to distributed computing capabilities and enable seamless resource sharing between users and platforms. This heterogeneous distribution of resources and the various modes of collaborations that exist between users, virtual organizations, and resource providers require scalable, flexible, and fine-grained access control to pro-tect both individual and shared computing resources. In this paper we propose a usage control (UCON) based authorization frame-work for collaborative applications. In our framework, usage con-trol policies are defined using subject and object attributes, along with system attributes as conditions. General attributes include not only persistent attributes such as role and group memberships, but also mutable usage attributes of subjects and objects. Conditions in UCON can be used to support context-based authorizations in ad-hoc collaborations. As a proof-of-concept we implement a pro-totype system based on our proposed architecture and conduct ex-perimental studies to demonstrate the feasibility and performance of our approach.