Privacy-preserving attribute-based access control for grid computing. (1st January 2014)
- Record Type:
- Journal Article
- Title:
- Privacy-preserving attribute-based access control for grid computing. (1st January 2014)
- Main Title:
- Privacy-preserving attribute-based access control for grid computing
- Authors:
- Park, Sang M.
Chung, Soon M. - Abstract:
- In Attribute-Based Access Control (ABAC), access is granted based on the attributes of the requesting user. ABAC is a highly flexible and scalable access control scheme which can deal with diverse security requirements in a grid computing environment. However, in ABAC the user attributes published by the identity providers for authorisation decision may cause some privacy violation. We developed an attribute release control mechanism to publish an optimal set of user attributes that are essential to access a desired resource (or service), while exposing the least amount of sensitive user information. To facilitate the selection of an optimal set of user attributes, we also developed a Web service, named Security Policy Publication Service (SPPS), which retrieves the access condition from the access control policies in eXtensible Access Control Markup Language (XACML) and converts it into a Disjunctive Normal Form (DNF) of user attributes. For the implementation of our privacy-preserving ABAC, we used the Globus Toolkit and modified the Shibboleth Identity Provider and GridShib. Our performance analysis shows that the overhead of the proposed system is very small.
- Is Part Of:
- International journal of grid and utility computing. Volume 5:Number 4(2014)
- Journal:
- International journal of grid and utility computing
- Issue:
- Volume 5:Number 4(2014)
- Issue Display:
- Volume 5, Issue 4 (2014)
- Year:
- 2014
- Volume:
- 5
- Issue:
- 4
- Issue Sort Value:
- 2014-0005-0004-0000
- Page Start:
- 286
- Page End:
- 296
- Publication Date:
- 2014-01-01
- Subjects:
- grid -- attribute-based access control -- privacy protection -- Shibboleth -- XACML
Electronic data processing -- Distributed processing -- Periodicals
Electronic commerce -- Management -- Computer programs -- Periodicals
004.605 - Journal URLs:
- http://www.inderscience.com/ ↗
http://www.inderscience.com/jhome.php?jcode=ijguc ↗ - Languages:
- English
- ISSNs:
- 1741-847X
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 7401.xml