MetaCartSign in to MyCiteSeer

Include Citations | Advanced Search | Help

Include Citations | Advanced Search | Help

  Implement role based access control with attribute certificates

Download:
Download as a PDF
by Wei Zhou, Christoph Meinel
http://www.informatik.uni-trier.de/~meinel/papers/Paper_code16.pdf
Add To MetaCart

Abstract:

Nowadays more and more activities are performed over the Internet. But as more people are involved in the transaction circle, security and authorization control becomes one of the biggest concerns. Hence, We are motivated by the need to manage and to enforce a strong authorization mechanism in largescale web-environment. Role based access control (RBAC) provides some flexibility to security management. Public key infrastructure (PKI) can provide a strong authentication. Privilege management infrastructure (PMI) as a new technology can provide strong authorization. In order to satisfy mentioned security requirements, we have established a role based access control infrastructure and developed a prototype that uses X.509 public key certificates (PKCs) and attribute certificates (ACs). Access control is performed by access control policies that are written in XML. Policies and roles are stored in ACs. PKCs and ACs are all stored in LDAP servers. A new solution for policy management is described. The main components of the prototype are administration tool and access control engine. The access control engine provides a service that mediates the data between the users and the resources, which is also responsible for authentication and authorization. The administration tool can create key pairs, PKCs and ACs, manage users ’ information, and so on.

Citations

160 A Community Authorization Service for Group Collaboration – Pearlman, Welch, et al. - 2002
102 An Internet Attribute Certificate Profile for Authorization. Internet RFC 3281 – Farrell, Housley - 2002
76 Role based access control models – Sandhu, Coyne, et al. - 1996
69 The PERMIS X.509 role based privilege management infrastructure – Chadwick - 2002
43 M.,“Using the KeyNote trust management system – Blaze - 1999
39 Certificate-based Authorization Policy in a PKI Environment – Thompson, Essiari, et al.
21 Role-based Access Control on the Web – Park, Sandhu, et al.
12 RBAC Policies in XML for X.509 Based Privilege Management – Chadwick - 2002
7 Venkata Bhamidipati, and Qamar Munawer. The ARBAC97 model for role-based aministration of roles – Sandhu - 1999
2 X.509 ISO/IEC 9594-8, The Directory: Public-key and Attribute Certificate Frameworks – Rec - 2001
1 Using a privilege management infrastructure for secure web-based e-health applications – Blobel, Hoepner, et al. - 2003
1 X.812(1995)|ISO/IEC 10181-3:1996, Security frameworks in open systems: Access control framework – Rec
1 Tomcat servlet container – Jakarta
1 the Open Source SQL database, http://www.mysql.com – MySQL