A combination of semantic and attribute-based access control model for virtual organizations

M. Amini, M. Arasteh
{"title":"A combination of semantic and attribute-based access control model for virtual organizations","authors":"M. Amini, M. Arasteh","doi":"10.22042/ISECURE.2015.7.1.4","DOIUrl":null,"url":null,"abstract":"A Virtual Organization (VO) consists of some real organizations with common interests, which aims to provide inter organizational associations to reach some common goals by sharing their resources with each other. Providing security mechanisms, and especially a suitable access control mechanism, which enforces the defined security policy is a necessary requirement in VOs. Since VO is a complex environment with the huge number of users and resources, traditional access control models cannot satisfy VOs security requirements. Most of the current proposals are basically based on the attributes of users and resources. In this paper, we suggest using a combination of the semantic based access control (SBAC) model, and the attribute based access control (ABAC) model with the shared ontology of subjects' attributes in VOs. In this model, each participating organization makes its access control decisions according to an enhanced model of the ABAC model. However, access decision in the VO is made in more abstract level through an enhanced model of theSBACmodel. Using the ontology of users and resources in this model facilitates access control in large scale VOs with numerous organizations. By the combination ofSBACand ABAC, we attain their benefits and eliminate their shortcomings. In order to show the applicability of the proposed model, an access control system, based on the proposed model, has been implemented in Java using available APIs, including Sun's XACML API, Jena, Pellet, and Protege.","PeriodicalId":436674,"journal":{"name":"ISC Int. J. Inf. Secur.","volume":"35 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-08-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ISC Int. J. Inf. Secur.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.22042/ISECURE.2015.7.1.4","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

A Virtual Organization (VO) consists of some real organizations with common interests, which aims to provide inter organizational associations to reach some common goals by sharing their resources with each other. Providing security mechanisms, and especially a suitable access control mechanism, which enforces the defined security policy is a necessary requirement in VOs. Since VO is a complex environment with the huge number of users and resources, traditional access control models cannot satisfy VOs security requirements. Most of the current proposals are basically based on the attributes of users and resources. In this paper, we suggest using a combination of the semantic based access control (SBAC) model, and the attribute based access control (ABAC) model with the shared ontology of subjects' attributes in VOs. In this model, each participating organization makes its access control decisions according to an enhanced model of the ABAC model. However, access decision in the VO is made in more abstract level through an enhanced model of theSBACmodel. Using the ontology of users and resources in this model facilitates access control in large scale VOs with numerous organizations. By the combination ofSBACand ABAC, we attain their benefits and eliminate their shortcomings. In order to show the applicability of the proposed model, an access control system, based on the proposed model, has been implemented in Java using available APIs, including Sun's XACML API, Jena, Pellet, and Protege.
基于语义和属性的虚拟组织访问控制模型
虚拟组织(Virtual Organization, VO)是由一些具有共同利益的真实组织组成的,其目的是通过组织间的资源共享来提供组织间的联系,以达到共同的目标。提供安全机制,特别是适当的访问控制机制,以执行已定义的安全策略,是vo中的必要要求。由于VO是一个复杂的环境,拥有大量的用户和资源,传统的访问控制模型无法满足VO的安全需求。目前大多数建议基本上都是基于用户和资源的属性。本文提出了基于语义的访问控制(SBAC)模型和基于属性的访问控制(ABAC)模型的结合,并提出了基于主体属性的共享本体。在该模型中,每个参与组织根据ABAC模型的增强模型做出访问控制决策。然而,VO中的访问决策是通过thesbac模型的增强模型在更抽象的级别上进行的。在该模型中使用用户和资源本体,便于对具有众多组织的大型vo进行访问控制。通过将sbac和ABAC相结合,我们得到了它们的优点,消除了它们的不足。为了显示所建议模型的适用性,一个基于所建议模型的访问控制系统已经在Java中使用可用的API实现,包括Sun的XACML API、Jena、Pellet和Protege。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信