|
|
Access Control in Ultra-Large-Scale Systems Using a Data-Centric Middleware
|
|
|
|
|
نویسنده
|
Shokrollahi Saeed ,Esmaeili Javad ,Shams Fereidoon
|
منبع
|
the isc international journal of information security - 2014 - دوره : 6 - شماره : 1 - صفحه:3 -22
|
چکیده
|
The primary characteristic of an ultra-large-scale (uls) system is ultra-large size on any related dimension. a uls system is generally considered as a system-of-systems with heterogeneous nodes and autonomous domains. as the size of a system-of-systems grows, and interoperability demand between sub-systems is increased, achieving more scalable and dynamic access control system becomes an important issue. the attribute-based access control (abac) model is a proper candidate to be used in such an access control system. the correct deployment and enforcement of abac policies in a uls system requires secure and scalable collaboration among dierent distributed authorization components. a large number of these authorization components should be able to join dierent domains dynamically and communicate with each other anonymously. dynamic conguration and reconfiguration of authorization components makes authorization system more complex to manage and maintain in a uls system. in this paper, an access control middleware is proposed to overcome the complexity of deployment and enforcement of abac policies in uls systems. the proposed middleware is data-centric and consists of two layers. the lower layer is a data-distribution-service (dds) middleware used for loosely-coupled-communication among authorization components. the upper layer is used for secure conguration and reconfiguration of authorization components. an executable model of the proposed middleware is also represented by a colored-petri-net (cpn) model. this executable model is used to analyze the behavior of the proposed middleware.
|
کلیدواژه
|
Access Control ,Colored-Petri-Nets Model ,Middleware ,Data-Distribution-Service Middleware ,Ultra- Large-Scale Systems.
|
آدرس
|
shahid beheshti university, Department of Computer Engineering, ایران, shahid beheshti university, Department of Computer Engineering, ایران, shahid beheshti university, Department of Computer Engineering, ایران
|
پست الکترونیکی
|
j-esmaeili@sbu.ac.ir
|
|
|
|
|
|
|
|
|
|
|
|
Authors
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|