Privacy Protection of Grid Service Requesters through Distributed Attribute Based Access Control Model
نویسندگان
چکیده
In Grid service environments, traditional identity based access control models are not effective, and access decisions need to be made based on service requesters’ attributes. All of previous attribute based access control (ABAC) models are lacking in protection of users’ privacy because in these models, access control decisions are made by providing the service provider with user attributes. This paper presents a Distributed Attribute Based Access Control (DABAC) model which protects users’ privacy in Grid service environments. The DABAC model is based on XACML access control framework. In DABAC model, access control is distributed between home organization (service requester’s organization) and destination organization (service provider’s organization). In this model, user attributes are examined in home organization for which policy certificates are provided. This prevents service provider from accessing users’ attributes. Therefore, users’ privacy is protected. Moreover, distributed nature of this model, makes it more efficient comparing with previous models.
منابع مشابه
Privacy and Anonymity Protection in Computational Grid Services
In computational grid computing, grid nodes spanning over several diverse computing resources belonging to heterogeneous administrative domains form the backbone of Virtual Enterprise [VE]. In order to offer service-on-demand, various service providers, requesters, brokers and administrators collaborate in request-response manner among each other in Service Oriented Virtual Enterprise through s...
متن کاملAttribute-based Access Control for Cloud-based Electronic Health Record (EHR) Systems
Electronic health record (EHR) system facilitates integrating patients' medical information and improves service productivity. However, user access to patient data in a privacy-preserving manner is still challenging problem. Many studies concerned with security and privacy in EHR systems. Rezaeibagha and Mu [1] have proposed a hybrid architecture for privacy-preserving accessing patient records...
متن کاملAn Architecture for Security and Protection of Big Data
The issue of online privacy and security is a challenging subject, as it concerns the privacy of data that are increasingly more accessible via the internet. In other words, people who intend to access the private information of other users can do so more efficiently over the internet. This study is an attempt to address the privacy issue of distributed big data in the context of cloud computin...
متن کاملA Role and Attribute Based Encryption Approach to Privacy and Security in Cloud Based Health Services
Cloud computing is a rapidly emerging computing paradigm which replaces static and expensive data centers, network and software infrastructure with dynamically scalable “cloud based” services offered by third party providers on an on-demand basis. However, with the potential for seemingly limitless scalability and reduced infrastructure costs comes new issues regarding security and privacy as p...
متن کاملA combination of semantic and attribute-based access control model for virtual organizations
A Virtual Organization (VO) consists of some real organizations with common interests, which aims to provide inter organizational associations to reach some common goals by sharing their resources with each other. Providing security mechanisms, and especially a suitable access control mechanism, which enforces the defined security policy is a necessary requirement in VOs. Since VO is a complex ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010