Achieving fine-grained access control in virtual organizations

N. Zhang, L. Yao, A. Nenadic, J. Chin, C. Goble, A. Rector, D. Chadwick, S. Otenko, Q. Shi

    Research output: Contribution to journalArticlepeer-review

    Abstract

    In a virtual organization environment, where services and data are provided and shared among organizations from different administrative domains and protected with dissimilar security policies and measures, there is a need for a flexible authentication framework that supports the use of various authentication methods and tokens. The authentication strengths derived from the authentication methods and tokens should be incorporated into an access-control decision-making process, so that more sensitive resources are available only to users authenticated with stronger methods. This paper reports our ongoing efforts in designing and implementing such a framework to facilitate multi-level and multi-factor adaptive authentication and authentication strength linked fine-grained access control. The proof-of-concept prototype is designed and implemented in the Shibboleth and PERMIS infrastructures, which specifies protocols to federate authentication and authorization information and provides a policy-driven, role-based, access-control decision-making capability. Copyright © 2006 John Wiley & Sons, Ltd.
    Original languageEnglish
    Pages (from-to)1333-1352
    Number of pages19
    JournalConcurrency and Computation: Practice & Experience
    Volume19
    Issue number9
    DOIs
    Publication statusPublished - 25 Jun 2007

    Keywords

    • Authentication
    • Authorization
    • PERMIS
    • Shibboleth
    • Smart tokens
    • Virtual organization

    Fingerprint

    Dive into the research topics of 'Achieving fine-grained access control in virtual organizations'. Together they form a unique fingerprint.

    Cite this