Abstract
For an efficient role based access control using attribute certificate in highly distributed computing environments, we use a technique of structuring role specification certificates. The roles are grouped and made them into the relation tree. It can reduce management cost and overhead incurred when changing the specification of the role. Further we use caching of frequently used role specification certificate for better performance in case applying the role. And for the global space reduction, we also consider the issue of tree normalization. In order to be scalable distribution of the role specification certificate, we use multicasting packets. In the experimental section, it is shown that our proposed method is secure and efficient.
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
ITI (Information Technology Industry Council), Role Based Access Control ITU/T. Recommendation X.509 | ISO/IEC 9594-8, Information Technology Open Systems Interconnec-tion-The Directory: Public-Key and Attribute Certificate Frameworks (2003)
Farrell, S., Housley, R.: An Internet Attribute Certificate Profile for Authorization, IETF RFC 3281 (2002)
Rafaeli, S., Hutchison, D.: A Survey of Key Management for Secure Group Communication. ACM Computing Surveys 35(3) (2003)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2006 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Yang, S. (2006). On the Security of Attribute Certificate Structuring for Highly Distributed Computing Environments. In: Kim, YT., Takano, M. (eds) Management of Convergence Networks and Services. APNOMS 2006. Lecture Notes in Computer Science, vol 4238. Springer, Berlin, Heidelberg. https://doi.org/10.1007/11876601_58
Download citation
DOI: https://doi.org/10.1007/11876601_58
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-45776-3
Online ISBN: 978-3-540-46233-0
eBook Packages: Computer ScienceComputer Science (R0)