Access Control Policies for Traceability Information Systems

نویسندگان

  • Miguel L. Pardal
  • Mark Harrison
  • Sanjay Sarma
  • José Alves Marques
چکیده

Traceability information systems need to collect and process data from multiple companies across the supply chain and many of the business partners are not known in advance. This open-ended security is, in principle, a good match for a Service-Oriented Architecture (SOA) design and for the use of Web Services (WS) technologies because they implement flexible and inter-operable systems based on services. However there is a gap between the visibility restrictions and the way to express them using standard WS technologies. This paper describes Supply Chain Authorization (SCAz), an interface developed to define and enforce visibility restrictions – access control policies – for supply chain systems. Several implementations are presented and the trade-offs are discussed. The performance of SCAz is assessed in the setting of an externalized security architecture by comparing raw authorization implementations with their equivalents translated to the standard language eXtensible Access Control Markup Language (XACML). The SCAz Chain-of-Trust Assertions (CTA) implementation is found to have similar performance to other approaches while allowing extensions such as delegated trust, transitive trust, conditional trust, and bulk trust.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Requirements-based Access Control Analysis and Policy Specification (ReCAPS)

Access control is a mechanism for achieving confidentiality and integrity in software systems. Access control policies (ACPs) are security requirements that define how access is managed and the high-level rules of who, under what conditions, can access what information. Traditionally, access control policies are often specified after a system is designed and deployed. Because ACP specification ...

متن کامل

Deriving Access Control Policies from Requirements Specifications and Database Designs

Access control is a mechanism for achieving confidentiality and integrity in software systems. Specifying access control policies (ACPs) is a complex process that can benefit from requirements engineering techniques. In this paper, we present a method for deriving access control policies from software requirements specifications (SRS) and database designs. The approach provides prescriptive gui...

متن کامل

Access control in ultra-large-scale systems using a data-centric middleware

  The primary characteristic of an Ultra-Large-Scale (ULS) system is ultra-large size on any related dimension. A ULS system is generally considered as a system-of-systems with heterogeneous nodes and autonomous domains. As the size of a system-of-systems grows, and interoperability demand between sub-systems is increased, achieving more scalable and dynamic access control system becomes an im...

متن کامل

An automatic test case generator for evaluating implementation of access control policies

One of the main requirements for providing software security is the enforcement of access control policies which aim to protect resources of the system against unauthorized accesses. Any error in the implementation of such policies may lead to undesirable outcomes. For testing the implementation of access control policies, it is preferred to use automated methods which are faster and more relia...

متن کامل

Fine-Grained Access Control for EPC Information Services

Inter-organizational exchange of information about physical objects that is automatically gathered using RFID can increase the traceability of goods in complex supply chains. With the EPCIS speci cation, a standard for RFID-based events and respective information system interfaces is available. However, it does not address access control in detail, which is a prerequisite for secure information...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013