Distributed Privilege Enforcement in PACS

dc.contributor.authorSturm, Christophdeu
dc.contributor.authorHunt, Eladeu
dc.contributor.authorScholl, Marc H.
dc.date.accessioned2011-03-24T16:11:32Zdeu
dc.date.available2011-03-24T16:11:32Zdeu
dc.date.issued2009
dc.description.abstractWe present a new access control mechanism for P2P networks with distributed enforcement, called P2P Access Control System (PACS). PACS enforces powerful access control models like RBAC with administrative delegation inside a P2P network in a pure P2P manner, which is not possible in any of the currently used P2P access control mechanisms. PACS uses client-side enforcement to support the replication of confidential data. To avoid a single point of failure at the time of privilege enforcement, we use threshold cryptography to distribute the enforcement among the participants. Our analysis of the expected number of messages and the computational effort needed in PACS shows that its increased flexibility comes with an acceptable additional overhead.eng
dc.description.versionpublished
dc.format.mimetypeapplication/pdfdeu
dc.identifier.citationFirst publ. in: Data and Applications Security XXIII : 23rd Annual IFIP WG 11.3 Working Conference, Montreal, Canada, July 12-15, 2009: proceedings / Ehud Gudes, Jaideep Vaidya (eds.). (Lecture Notes in Computer Science ; 5645) New York: Springer, 2009, pp. 142-158deu
dc.identifier.doi10.1007/978-3-642-03007-9_10
dc.identifier.ppn320437558deu
dc.identifier.urihttp://kops.uni-konstanz.de/handle/123456789/6338
dc.language.isoengdeu
dc.legacy.dateIssued2010deu
dc.rightsterms-of-usedeu
dc.rights.urihttps://rightsstatements.org/page/InC/1.0/deu
dc.subject.ddc004deu
dc.subject.gndDatenbankdeu
dc.subject.gndDatenbanksystemdeu
dc.subject.gndDatenbankverwaltungdeu
dc.subject.gndRollenbasierte Zugriffskontrolledeu
dc.subject.gndZugriffskontrolledeu
dc.subject.gndPeer-to-Peer-Netzdeu
dc.subject.gndDatenverwaltungdeu
dc.titleDistributed Privilege Enforcement in PACSeng
dc.typeINPROCEEDINGSdeu
dspace.entity.typePublication
kops.citation.bibtex
@inproceedings{Sturm2009Distr-6338,
  year={2009},
  doi={10.1007/978-3-642-03007-9_10},
  title={Distributed Privilege Enforcement in PACS},
  number={5645},
  isbn={978-3-642-03006-2},
  publisher={Springer Berlin Heidelberg},
  address={Berlin, Heidelberg},
  series={Lecture Notes in Computer Science},
  booktitle={Data and Applications Security XXIII},
  pages={142--158},
  editor={Gudes, Ehud and Vaidya, Jaideep},
  author={Sturm, Christoph and Hunt, Ela and Scholl, Marc H.}
}
kops.citation.iso690STURM, Christoph, Ela HUNT, Marc H. SCHOLL, 2009. Distributed Privilege Enforcement in PACS. In: GUDES, Ehud, ed., Jaideep VAIDYA, ed.. Data and Applications Security XXIII. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009, pp. 142-158. Lecture Notes in Computer Science. 5645. ISBN 978-3-642-03006-2. Available under: doi: 10.1007/978-3-642-03007-9_10deu
kops.citation.iso690STURM, Christoph, Ela HUNT, Marc H. SCHOLL, 2009. Distributed Privilege Enforcement in PACS. In: GUDES, Ehud, ed., Jaideep VAIDYA, ed.. Data and Applications Security XXIII. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009, pp. 142-158. Lecture Notes in Computer Science. 5645. ISBN 978-3-642-03006-2. Available under: doi: 10.1007/978-3-642-03007-9_10eng
kops.citation.rdf
<rdf:RDF
    xmlns:dcterms="http://purl.org/dc/terms/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:bibo="http://purl.org/ontology/bibo/"
    xmlns:dspace="http://digital-repositories.org/ontologies/dspace/0.1.0#"
    xmlns:foaf="http://xmlns.com/foaf/0.1/"
    xmlns:void="http://rdfs.org/ns/void#"
    xmlns:xsd="http://www.w3.org/2001/XMLSchema#" > 
  <rdf:Description rdf:about="https://kops.uni-konstanz.de/server/rdf/resource/123456789/6338">
    <dcterms:bibliographicCitation>First publ. in: Data and Applications Security XXIII : 23rd Annual IFIP WG 11.3 Working Conference, Montreal, Canada, July 12-15, 2009: proceedings / Ehud Gudes, Jaideep Vaidya (eds.). (Lecture Notes in Computer Science ; 5645) New York: Springer, 2009, pp. 142-158</dcterms:bibliographicCitation>
    <dcterms:rights rdf:resource="https://rightsstatements.org/page/InC/1.0/"/>
    <dc:creator>Sturm, Christoph</dc:creator>
    <dc:date rdf:datatype="http://www.w3.org/2001/XMLSchema#dateTime">2011-03-24T16:11:32Z</dc:date>
    <dcterms:isPartOf rdf:resource="https://kops.uni-konstanz.de/server/rdf/resource/123456789/36"/>
    <dcterms:issued>2009</dcterms:issued>
    <dcterms:available rdf:datatype="http://www.w3.org/2001/XMLSchema#dateTime">2011-03-24T16:11:32Z</dcterms:available>
    <dspace:hasBitstream rdf:resource="https://kops.uni-konstanz.de/bitstream/123456789/6338/1/SHS_DAS09.pdf"/>
    <dc:format>application/pdf</dc:format>
    <dcterms:abstract xml:lang="eng">We present a new access control mechanism for P2P networks with distributed enforcement, called P2P Access Control System (PACS). PACS enforces powerful access control models like RBAC with administrative delegation inside a P2P network in a pure P2P manner, which is not possible in any of the currently used P2P access control mechanisms. PACS uses client-side enforcement to support the replication of confidential data. To avoid a single point of failure at the time of privilege enforcement, we use threshold cryptography to distribute the enforcement among the participants. Our analysis of the expected number of messages and the computational effort needed in PACS shows that its increased flexibility comes with an acceptable additional overhead.</dcterms:abstract>
    <dc:contributor>Hunt, Ela</dc:contributor>
    <foaf:homepage rdf:resource="http://localhost:8080/"/>
    <dc:creator>Scholl, Marc H.</dc:creator>
    <dc:rights>terms-of-use</dc:rights>
    <void:sparqlEndpoint rdf:resource="http://localhost/fuseki/dspace/sparql"/>
    <bibo:uri rdf:resource="http://kops.uni-konstanz.de/handle/123456789/6338"/>
    <dc:language>eng</dc:language>
    <dc:contributor>Scholl, Marc H.</dc:contributor>
    <dc:creator>Hunt, Ela</dc:creator>
    <dc:contributor>Sturm, Christoph</dc:contributor>
    <dcterms:hasPart rdf:resource="https://kops.uni-konstanz.de/bitstream/123456789/6338/1/SHS_DAS09.pdf"/>
    <dcterms:title>Distributed Privilege Enforcement in PACS</dcterms:title>
    <dspace:isPartOfCollection rdf:resource="https://kops.uni-konstanz.de/server/rdf/resource/123456789/36"/>
  </rdf:Description>
</rdf:RDF>
kops.description.openAccessopenaccessgreen
kops.flag.knbibliographytrue
kops.identifier.nbnurn:nbn:de:bsz:352-opus-108951deu
kops.opus.id10895deu
kops.sourcefieldGUDES, Ehud, ed., Jaideep VAIDYA, ed.. <i>Data and Applications Security XXIII</i>. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009, pp. 142-158. Lecture Notes in Computer Science. 5645. ISBN 978-3-642-03006-2. Available under: doi: 10.1007/978-3-642-03007-9_10deu
kops.sourcefield.plainGUDES, Ehud, ed., Jaideep VAIDYA, ed.. Data and Applications Security XXIII. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009, pp. 142-158. Lecture Notes in Computer Science. 5645. ISBN 978-3-642-03006-2. Available under: doi: 10.1007/978-3-642-03007-9_10deu
kops.sourcefield.plainGUDES, Ehud, ed., Jaideep VAIDYA, ed.. Data and Applications Security XXIII. Berlin, Heidelberg: Springer Berlin Heidelberg, 2009, pp. 142-158. Lecture Notes in Computer Science. 5645. ISBN 978-3-642-03006-2. Available under: doi: 10.1007/978-3-642-03007-9_10eng
relation.isAuthorOfPublication79d29015-25f9-4ec2-bc8e-77a0c07303ba
relation.isAuthorOfPublication.latestForDiscovery79d29015-25f9-4ec2-bc8e-77a0c07303ba
source.bibliographicInfo.fromPage142
source.bibliographicInfo.seriesNumber5645
source.bibliographicInfo.toPage158
source.contributor.editorGudes, Ehud
source.contributor.editorVaidya, Jaideep
source.identifier.isbn978-3-642-03006-2
source.publisherSpringer Berlin Heidelberg
source.publisher.locationBerlin, Heidelberg
source.relation.ispartofseriesLecture Notes in Computer Science
source.titleData and Applications Security XXIII

Dateien

Originalbündel

Gerade angezeigt 1 - 1 von 1
Vorschaubild nicht verfügbar
Name:
SHS_DAS09.pdf
Größe:
457.67 KB
Format:
Adobe Portable Document Format
SHS_DAS09.pdf
SHS_DAS09.pdfGröße: 457.67 KBDownloads: 276