The Center for Education and Research in Information Assurance and Security (CERIAS)

The Center for Education and Research in
Information Assurance and Security (CERIAS)

X-GTRBAC: An XML-Based Policy Specification Framework and Architecture for Enterprise-Wide Access Control

Download

Download PDF Document
PDF

Author

Rafae Bhatti

Tech report number

CERIAS TR 2003-27

Entry type

mastersthesis

Abstract

Modern day enterprises exhibit a growing trend toward adoption of enterprise computing services for efficient resource utilization, scalability and flexibility. These environments are characterized by heterogeneous, distributed computing systems exchanging enormous volumes of time-critical data with varying levels of access control in a dynamic business environment. The enterprises are thus faced with significant challenges as they endeavor to achieve their primary goals, and simultaneously ensure enterprise-wide secure interoperation among the various collaborating entities. Key among these challenges are providing effective mechanism for enforcement of enterprise policy across distributed domains, ensuring secure content-based access to enterprise resources at all user levels, and allowing the specification of temporal and non-temporal context conditions to support fine-grained dynamic access control. This thesis investigates these challenges, and presents X-GTRBAC, an XML-based GTRBAC policy specification language and its implementation for enforcing enterprise-wide access control. Our specification language is based on the GTRBAC model that incorporates the content- and context-aware dynamic access control requirements of an enterprise. An X-GTRBAC system has been implemented as a Java application. We discuss the salient features of the specification language, and present the software architecture of our system. A comprehensive example is included to discuss and motivate the applicability of the X-GTRBAC framework to a generic enterprise environment. An application level interface for implementing the policy in the X-GTRBAC system is also provided to consolidate the ideas presented in the thesis.

Download

PDF

Institution

Purdue University

Key alpha

XML Access Control

School

Electrical and Computer Engineering

Publication Date

1900-01-01

Subject

Enterprise Access Control

BibTex-formatted data

To refer to this entry, you may select and copy the text below and paste it into your BibTex document. Note that the text may not contain all macros that BibTex supports.