Abstract
In a virtual organization environment, where services and data are provided and shared among organizations from different administrative domains and protected with dissimilar security policies and measures, there is a need for a flexible authentication framework that supports the use of various authentication methods and tokens. The authentication strengths derived from the authentication methods and tokens should be incorporated into an access-control decision-making process, so that more sensitive resources are available only to users authenticated with stronger methods. This paper reports our ongoing efforts in designing and implementing such a framework to facilitate multi-level and multi-factor adaptive authentication and authentication strength linked fine-grained access control. The proof-of-concept prototype is designed and implemented in the Shibboleth and PERMIS infrastructures, which specifies protocols to federate authentication and authorization information and provides a policy-driven, role-based, access-control decision-making capability. Copyright © 2006 John Wiley & Sons, Ltd.
Original language | English |
---|---|
Pages (from-to) | 1333-1352 |
Number of pages | 19 |
Journal | Concurrency and Computation: Practice & Experience |
Volume | 19 |
Issue number | 9 |
DOIs | |
Publication status | Published - 25 Jun 2007 |
Keywords
- Authentication
- Authorization
- PERMIS
- Shibboleth
- Smart tokens
- Virtual organization