Full Text:   <2002>

CLC number: TP309.2

On-line Access: 2010-09-07

Received: 2009-09-14

Revision Accepted: 2009-12-07

Crosschecked: 2010-08-02

Cited: 3

Clicked: 5146

Journal of Zhejiang University SCIENCE C 2010 Vol.11 No.9 P.699-717


An authorization model for collaborative access control

Author(s):  Chen-hua Ma, Guo-dong Lu, Jiong Qiu

Affiliation(s):  Engineering and Computer Graphics Institute, Zhejiang University, Hangzhou 310027, China, Department of Computer Science and Technology, Hangzhou Dianzi University, Hangzhou 310018, China

Corresponding email(s):   mchma@zju.edu.cn

Key Words:  Collaborative access control, Collaborative permission, Conflict detection and resolution

collaborative access control is receiving growing attention in both military and commercial areas due to an urgent need to protect confidential resources and sensitive tasks. collaborative access control means that multiple subjects should participate to make access control decisions to prevent fraud or the abuse of rights. Existing approaches to access control cannot satisfy the requirements of collaborative access control. To address this concern, we propose an authorization model for collaborative access control. The central notions of the model are collaborative permission, collaboration constraint, and collaborative authorization policy, which make it possible to define the collaboration among multiple subjects involved in gaining a permission. The implementation architecture of the model is also provided. Furthermore, we present effective conflict detection and resolution methods for maintaining the consistency of collaborative authorization policies.

