A Scalable Permission Management System With Support of Conditional and Customized Attributes

04/17/2018
by   Baiyu Liu, et al.
0

Along with the classical problem of managing multiple identities, actions, devices, APIs etc. in different businesses, there has been an escalating need for having the capability of flexible attribute based access control (ABAC) mechanisms. In order to fill this gap, several variations of ABAC model have been proposed such as Amazon's AWS IAM, which uses JSON as their underlying storage data structure and adds policies/constraints as fields over the regular ABAC. However, these systems still do not provide the capability to have customized permissions and to perform various operations (such as comparison/aggregation) on them. In this paper, we introduce a string based resource naming strategy that supports the customized and conditional permissions for resource access. Further, we propose the basic architecture of our system which, along with our naming scheme, makes the system scalable, secure, efficient, flexible and customizable. Finally, we present the proof of concept for our algorithm as well as the experimental set up and the future trajectory for this work.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/01/2018

A Federated Capability-based Access Control Mechanism for Internet of Things (IoTs)

The prevalence of Internet of Things (IoTs) allows heterogeneous embedde...
research
08/19/2021

Decentralized Policy Information Points for Multi-Domain Environments

Access control models have been developed to control authorized access t...
research
07/21/2021

HUAP: Practical Attribute-based Access Control Supporting Hidden Updatable Access Policies for Resource-Constrained Devices

Attribute-based encryption (ABE) is a promising cryptographic mechanism ...
research
07/16/2018

Tiered Object Storage using Persistent Memory

Most data intensive applications often access only a few fields of the o...
research
08/31/2023

A Customizable Conflict Resolution and Attribute-Based Access Control Framework for Multi-Robot Systems

As multi-robot systems continue to advance and become integral to variou...
research
04/10/2022

AABAC – Automated Attribute Based Access Control for Genomics Data

The COVID-19 crisis has demonstrated the potential of cutting-edge genom...
research
01/16/2019

Fundamentals of effective cloud management for the new NASA Astrophysics Data System

The new NASA Astrophysics Data System (ADS) is designed with a serviceor...

Please sign up or login with your details

Forgot password? Click here to reset