An authorization model for collaborative access control

作者:Ma, Chen-hua*; Lu, Guo-dong; Qiu, Jiong
来源:Journal of Zhejiang University-Science C(Computers and Electronics), 2010, 11(9): 699-717.
DOI:10.1631/jzus.C0910564

摘要

Collaborative access control is receiving growing attention in both military and commercial areas due to an urgent need to protect confidential resources and sensitive tasks. Collaborative access control means that multiple subjects should participate to make access control decisions to prevent fraud or the abuse of rights. Existing approaches to access control cannot satisfy the requirements of collaborative access control. To address this concern, we propose an authorization model for collaborative access control. The central notions of the model are collaborative permission, collaboration constraint, and collaborative authorization policy, which make it possible to define the collaboration among multiple subjects involved in gaining a permission. The implementation architecture of the model is also provided. Furthermore, we present effective conflict detection and resolution methods for maintaining the consistency of collaborative authorization policies.