O2O: Virtual Private Organizations to Manage Security Policy Interoperability
نویسندگان
چکیده
Nowadays, the interaction between systems is absolutely essential to achieve business continuity. There is a need to exchange and share services and resources. Unfortunately, this does not come without security problems. The organizations (companies, enterprizes, etc.) have to manage accesses to their services and resources by external opponents. O2O is a formal approach we suggest in this paper to deal with access control in an interoperability context. It is based on two main concepts: Virtual Private Organization (VPO) and Role Single-Sign On (RSSO). A VPO enables any organization undertaking an inter-operation with other organizations to keep control over the ressources accessed during the interoperability phases. The RSSO principle allows a given subject to keep the same role when accessing to another organization but with privileges defined in the VPO. Thus, using O2O, each organization can define and enforce its own secure interoperability policy. O2O is integrated in the OrBAC model (Organization based access control). keywords: Virtual Organization (VO), Virtual Private Organization (VPO), Role Single Sign On (RSSO), OrBAC, Access Control, Authority spheres, Interoperability
منابع مشابه
O2O: Managing Security Policy Interoperability with Virtual Private Organizations
Nowadays, the interaction between systems is absolutely essential to achieve business continuity due to the need of exchanging and sharing services and resources. Unfortunately, this does not come without security problems. The organizations (companies, enterprizes, etc.) have to manage accesses to their services and resources by external opponents. O2O is a formal approach we suggest in this p...
متن کاملSecure interoperation with O2O contracts
The evolution of today’s markets and the high volatility of business requirements put an increasing emphasis on the ability for systems to accommodate the changes required by new organizational needs while maintaining security objectives satisfiability. This is all the more true in case of collaboration and interoperability between different organizations and thus between their information syst...
متن کاملVirtual organization security policies: An ontology-based integration approach
This paper addresses the specification of a security policy ontology framework to mediate security policies between virtual organizations (VO) and real organizations (RO). The goal is to develop a common domain model for security policy via semantic mapping. This mitigates interoperability problems that exist due to heterogeneity in security policy data among various (VO) and (RO) in the semant...
متن کاملA combination of semantic and attribute-based access control model for virtual organizations
A Virtual Organization (VO) consists of some real organizations with common interests, which aims to provide inter organizational associations to reach some common goals by sharing their resources with each other. Providing security mechanisms, and especially a suitable access control mechanism, which enforces the defined security policy is a necessary requirement in VOs. Since VO is a complex ...
متن کاملProposed Conceptual Development Levels for Ideal Interoperability and Security in Modern Digital Government
This paper appraises the status of the advanced art in the section of attractive digital government interoperability and security by means of widespread models. Interoperability proposes to the exercise of Information and Communication Technologies to smooth the progress of the harmonization of work and information flow. Interoperability articulates to a property of special systems and organiza...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2006