Current mechanisms for distributed access management are limited in their capabilities to provide federated information sharing while ensuring adequate levels of resource protection. This work presents a policy-based framework designed to address these limitations for access management in federated systems. In particular, it supports: (i) decentralized administration while preserving local autonomy, (ii) fine-grained access control while avoiding rule-explosion in the policy,(iii) credential federation through the use of interoperable protocols, with support for single sign on for federated users, (iv) specification and enforcement of semantic and contextual constraints to support integrity requirements and contractual obligations, and (v) usage control in resource provisioning through effective session management. The paper highlights the significance of our policy-based approach in comparison with related mechanisms. It also presents a system architecture of our implementation prototype.
CITATION STYLE
Bhatti, R., Bertino, E., & Ghafoor, A. (2005). A Policy Framework for Access Management in Federated Information Sharing. IFIP Advances in Information and Communication Technology, 193, 95–120. https://doi.org/10.1007/0-387-31167-x_7
Mendeley helps you to discover research relevant for your work.