Modular authorization

17Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.
Get full text

Abstract

There are three major drawbacks of a centralized security administration in distributed systems: It creates a bottle-neck for request handling, it tends to enforce homogeneous security structures in heterogeneous user groups and organizations, and it is a weak point in terms of security attacks, reliability, and fault tolerance. In this paper we introduce a distributed authorization concept which is based on a modular authorization language for supporting cooperating distributed authorization teams. These teams are partially ordered into a hierarchy in that they inherit authorization rules from higher order teams but still exercise their autonomy by (dynamically) setting local rules that serve the special local needs in distributed organizations. Conflicts between between rules inherited from different higher ranking sources, or violations of higher order rules through local rules would be detected, on the logical level or through request evaluation, as contradictions or contradicting results, respectively. Conflict resolution mechanisms are presented, and examples are discussed extensively.

Cite

CITATION STYLE

APA

Wedde, H. F., & Lischka, M. (2001). Modular authorization. In Proceedings of Sixth ACM Symposium on Access Control Models and Technologies (SACMAT 2001) (pp. 97–105). Association for Computing Machinery (ACM). https://doi.org/10.1145/373256.373274

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free