手机版

A Framework for Role-Based Access Control in Group Communica

时间:2025-07-04   来源:未知    
字号:

In this paper we analyze the requirements access control mechanisms must fulfill in the context of group communication and define a framework for supporting fine-grained access control in client-server group communication systems. Our framework combines ro

AFrameworkforRole-BasedAccessControlinGroup

CommunicationSystems

CristinaNita-RotaruandNinghuiLiDepartmentofComputerSciences

PurdueUniversityWestLafayette,IN47907

Abstract

Inthispaperweanalyzetherequirementsaccesscontrolmechanismsmustful llinthecontextofgroupcommunicationandde neaframeworkforsupporting ne-grainedaccesscontrolinclient-servergroupcom-municationsystems.Ourframeworkcombinesrole-basedaccesscontrolmechanismswithenvironmentpa-rameters(time,IPaddress,etc.)toprovidesupportforawiderangeofapplicationswithverydi erentre-quirements.Whiletheaccesscontrolpolicyisde nedbytheapplication,itse cientenforcementisprovidedbythegroupcommunicationsystem.

1Introduction

Manycollaborativeapplicationssuchasphoneandvideoconferencing,white-boards,distance-learningapplications,games,sharedinstrumentcontrol,aswellascommand-and-controlsystems,haveincommontheneedforacommunicationinfrastructurethatpro-videse cientmessagedisseminationtomultiplepar-ties(oftenorganizedingroupsbasedonacommonin-terest),e cientsynchronizationmechanismsthatal-lowforcoordinationandlast,butnotleast,securityservices.Groupcommunicationsystems(GCS)pro-videsuchservices.Examplesofgroupcommunica-tionsystemsinclude:ISIS[9],Horus[21],Transis[4],Totem[6],RMP[28],Rampart[20],SecureRing[13],Ensemble[24]andSpread[8,3].

Animportantaspectforsecurecollaborativegroupsisde ningandenforcingasecuritypolicy.Asetofdef-initionsandrequirementsofsecuritypoliciesingroupsispresentedin[12].Theminimalsetofsecurityser-vicesthatshouldbeprovidedbyanysecureGCSandshouldbespeci edinagrouppolicyinclude:clientau-thentication,accesscontrol,groupkeymanagement,dataintegrityandcon dentiality.

Whileconsiderableresearchhasbeenconductedto

designscalableandfault-tolerantgroupkeymanage-mentprotocols[29,23,5],andtoprovidedatacon -dentialityandintegrity[17,2,25,7]forgroups,lessworkfocusedontheaccesscontrolservices.WhenGCSareusedasacommonplatformbyseveralap-plicationswithdi erentsecurityrequirements,thereisanobviousneedtocontrolwhocanjoinagroup,whocansend/receivemessages,etc.MajorchallengeswhenprovidingaccesscontrolservicestoGCSarerec-onciling exibilitywithscalability,ande cientlyen-forcingaccesscontrolinthecontextofdynamicanddistributedgroupswhilesupportingprocessfailuresandnetworkpartitions.

MostexistingworkinprovidingaccesscontrolforgroupsemploystraditionalaccesscontrolschemessuchasAccessControlLists(ACL’s).Suchschemesmakeauthorizationdecisionsbasedontheidentityoftherequester.However,indecentralizedormulti-centricenvironments,theresourceownerandtherequesterareoftenunknowntooneanother,makingaccesscon-trolbasedonidentityine ectiveorveryexpensivetomaintain.

Weadoptanapproachinwhichtheoperationsaclientisallowedtoperformdependsontheroletheclientisplayinginthegroup,andauthenticatedat-tributesoftheclientareusedtodeterminewhichrolestheclientcanplayinagroup.WefocusonaGCSus-ingaclient-serverarchitecturewherethedistributedprotocolsarerunbetweenasetofserversprovidingservicestonumerousclients.Morespeci cally,ourcontributionsare:

WeinvestigatetherequirementsforaccesscontrolmechanismsinGCSandshowwhyidentity-basedschemesdonotprovideenough exibilitytosup-portalargeclassofcollaborativeapplications. Wedesigna ne-grainedaccesscontrolframeworkforGCS,basedonideasinRole-BasedAccessControl[26,10]andRT[15],aRole-BasedTrust-Managementlanguage.Ourframeworkallowsan

…… 此处隐藏:1569字,全部文档内容请下载后查看。喜欢就下载吧 ……
A Framework for Role-Based Access Control in Group Communica.doc 将本文的Word文档下载到电脑,方便复制、编辑、收藏和打印
×
二维码
× 游客快捷下载通道(下载后可以自由复制和排版)
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
注:下载文档有可能出现无法下载或内容有问题,请联系客服协助您处理。
× 常见问题(客服时间:周一到周五 9:30-18:00)