HGAA: An Architecture to Support Hierarchical Group and Attribute-Based Access Control

CODASPY '18: Eighth ACM Conference on Data and Application Security and Privacy Tempe AZ USA March, 2018(2018)

引用 5|浏览8
暂无评分
摘要
Attribute-Based Access Control (ABAC), a promising alternative to traditional models of access control, has gained significant attention in recent academic literature. This attention has lead to the creation of a number of ABAC models including our previous contribution, Hierarchical Group and Attribute-Based Access Control (HGABAC). However, to date few complete solutions exist that provide both an ABAC model and architecture that could be implemented in real life scenarios. This work aims to advance progress towards a complete ABAC solution by introducing Hierarchical Group Attribute Architecture (HGAA), an architecture to support HGABAC and close the gap between a model and real world implementation. In addition to HGAA we also present an attribute certificate specification that enables users to provide proof of attribute ownership in a pseudonymous and off-line manner, as well as an update to the Hierarchical Group Policy Language (HGPL) to support our namespace for uniquely identifying attributes across disparate security domains. Details of our HGAA implementation are given and a preliminary analysis of its performance is discussed as well as directions for future work.
更多
查看译文
关键词
ABAC, Attribute-Based Access Control, HGABAC, Hierarchical Group and Attribute-Based Access Control, Architecture, Access Control, Attribute Certificate, Attribute Authority, HGAA, Hierarchical Group Attribute Architecture
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要