IACCESS · Interactive access control with Trust Management for pervasive autonomic Networks
FP6 — Marie Curie Actions (Human Resources and Mobility)
- Duration
- 2007-04-01 → 2009-03-31
- EU contribution
- €130,778
- Participants
- 1
- Scheme
- EIF
Lines connect the coordinator with its partners.
Results in brief
Final Activity Report Summary - IACCESS (Interactive access control with Trust Management for pervasive autonomic Networks)
The fellowship targets autonomic networks with main feature on demand federation of resources, and on demand integration of services in response to a request or a goal. An autonomic network is composed of entities with heterogeneous systems and with no unified security requirements. Each entity is responsible for the management and enforcement of its own security settings. The goal of the project is to provide a novel access control model that leverages on demand federation of services and resources in highly dynamic environments. Two research directions are addressed - an access control model for bilateral automated negotiation of access rights, and an access control model for dynamic coalition formations based on multilateral semantic interoperability of credentials. Theoretical formulation of an interactive access control model, its implementation and quantitative assessment has been successfully performed. A negotiation scheme for automated access rights establishment has been developed, implemented and tested. It has been successfully released a first version of an IACCESS prototype for automated trust negotiation. The prototype conforms to X.509 and SAML standards. Software libraries have been released under the GNU Lesser General Public License. The IACCESS software has been successfully integrated within a Grid monitoring system, leading to a new credential-based authorisation system for Grid. The novelty of the system is its granularity of authorisation: a coarse-grained level controls access to computational services; and a fine-grained level monitors the behaviour of applications executed by a computational service. The system guarantees that users (and their applications) authorised on the coarse-grained level behave as expected on the fine-grained level. It has been defined a new research line on a new platform-driven approach for scalable and interoperable access control for highly dynamic coalition formations. Dynamic coalitions allow small and medium enterprises to be more innovative and competitive in the market, adapting to new opportunities in a dynamic business environment. The research investigated on necessary underlying access control models and technologies allowing for automated coalition formation and operation. The challenge ahead is to facilitate consistent access control process within a coalition formation considering the heterogeneity of security models and requirements protecting partners' resources.
Data: CORDIS, © European Union
Project objective
An autonomic network is characterized by the self-management and self-configuration of its constituent nodes. In an autonomic network each node is responsible for the management and enforcement of its own security policies with a high degree of autonomy. The major feature of an autonomic network is the on demand federation and integration of heterogeneous services with no central authority and no unified security infrastructure. This autonomic scenario poses new security challenges that require novel environment- and self-aware (fine-grained) access and trust management model, which will be the subject of the research proposal.Interactive Access Control model (IAC) helps servers to compute on the fly missing credentials needed for a client to get access to a service. In cases of arbitrary (non-monotonic) security policies the model detects inconsistent policy states and performs a recovery step by finding conflicting credentials that violate the policy. The work on Semantic Access Control (SAC) considers semantic properties of clients, resources, context and credentials in order to face interoperability of authorizations between different application domains. The challenges placed ahead are to investigate and explore possible synergies between IAC and SAC models in order to provide novel access and trust management model for highly dynamic autonomic networks.The new model will protect security interests with respect to disclosure of information and access control on client and server sides, thus allowing two entities to automatically negotiate requirements (establish mutual trust) to access a service. Finally, a prototype implementation will be developed. It will be performed experimental assessments on running performance, feasibility and scalability in order to justify, improve and conclude the effectiveness of the research proposal.
Original text from CORDIS.
Participants
- Universidad de Málaga · MálagaCoordinatorSpain
Links
Data: CORDIS, © European Union
