Publication:
Enable delegation for RBAC with secure authorization certificate

No Thumbnail Available

Date

2011-11

Authors

Zhou, GuangXu
Demirer, Murat
Bayrak, Coşkun
Wang, Licheng

Journal Title

Journal ISSN

Volume Title

Publisher

Elsevier Advanced Technology, Oxford Fulfillment Centre The Boulevard, Langford Lane, Kidlington, Oxford Ox5 1Gb, Oxon, England

Research Projects

Organizational Units

Journal Issue

Abstract

Our motivation in this paper is to explore a Secure Delegation Scheme that could keep access control information hidden through network transmission. This approach introduces the quasirandom structure, 3-Uniform Hypergraph, as the representation structure for authorization information. It generates a Secure Authorization Certificate (SAC) in place of an Attribute Certificate (AC) to enable both Role-based Access Control (RBAC) and a delegation process for hiding authorization information. We have two contributions in this regard: (1) a value-based delegation scheme and (2) a pattern-based RBAC. A Secure Delegation Scheme is based on the hashing values generated with the quasirandom structure. With this scheme, the delegation process will greatly reduce the risk of sensitive authorization information leakage for applications. In the case of pattern-based access, we introduce a new hash function using quasirandom structure to make a fingerprint(1) for RBAC. The quasirandom structure derived from k-Uniform Hypergraph has measurable uniformity, which is an advantage over traditional hash functions. Another advantage is that it does not need to access the entire message context to generate the fingerprint which is essential for traditional hash functions such as MD5, SHA-1, etc. (C) 2011 Elsevier Ltd. All rights reserved.

Description

Keywords

Access Control, Computer Network Security, Random Number Generator, Secure Authorization, Secure Delegation, Quasirandom Structures, K-uniform Hypergraph, Regularity, Trust, Giriş Kontrolu, Bilgisayar Ağ Güvenliği, Rasgele Sayı Üreteci, Güvenli Yetkilendirme, Güvenli Heyeti, Quasirandom Yapıları, K Düzgün Hypergraph, Düzenlilik, Güven

Citation