The PERMIS X.509 role based privilege management infrastructure

被引:77
作者
Chadwick, DW [1 ]
Otenko, A [1 ]
机构
[1] Univ Salford, IS Inst, Manchester M5 4WT, Lancs, England
来源
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE | 2003年 / 19卷 / 02期
基金
英国工程与自然科学研究理事会;
关键词
trust management; X.509; attribute certificates; role based access controls; XML; privilege management infrastructure;
D O I
10.1016/S0167-739X(02)00153-X
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper describes the EC PERMIS project, which has developed a role based access control infrastructure that uses X.509 attribute certificates (ACs) to store the users' roles. All access control decisions are driven by an authorisation policy, which is itself stored in an X.509 AC, thus guaranteeing its integrity. All the ACs can be stored in one or more LDAP directories, thus making them widely available. Authorisation policies are written in XML according to a DTD that has been published at XML.org. The Access Control Decision Function (ADF) is written in Java and the Java API is simple to use, comprising of just three methods and a constructor. There is also a Privilege Allocator, which is a tool that constructs and signs ACs and stores them in an LDAP directory for subsequent use by the ADF (C) 2002 Elsevier Science B.V. All rights reserved.
引用
收藏
页码:277 / 289
页数:13
相关论文
共 23 条
[1]  
Adams C., 1999, Understanding Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations
[2]  
[Anonymous], P SACMAT 2002
[3]  
BERTINO E, 2001, P 6 ACM S ACC CONTR
[4]  
BLAZE M, 1999, KEYNOTE TRUST MANAGE
[5]  
Chadwick DW, 2002, INT FED INFO PROC, V86, P39
[6]  
DARNIANOU N, 1995, LECT NOTES COMPUT SC, P18
[7]  
EASTLAKE D, 2002, EXTENSIBLE MARKUP LA
[8]  
ERDOS M, SHIBBOLETH ARCHITECT
[9]  
FARRELL S, 2001, INTERNET ATTRIBUTE C
[10]   Access control in an open distributed environment [J].
Hayton, RJ ;
Bacon, JM ;
Moody, K .
1998 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS, 1998, :3-14