Business-Driven Enterprise Authorization - Moving Towards a Unified Authorization Architecture
نویسنده
چکیده
Information systems of large enterprises experience a shift from an application-centric architecture towards a focus on process orientation and web services. The information system is opened to business partners to allow for self-management and seamless cross-enterprise process integration. Aiming at higher flexibility and lower costs, this strategy also produces great new challenges the security and administrative support systems have to cope with. The security of the enterprise system has to keep up and scale with the new qualitive level of the overall system. In this context we propose an enterprise authorization system model which allows a unified treatment of the enterprise’s authorization issues, and permits the native integration of authorization processes into the business system for greater synergy. The proposed model supports information system architects to avoid that authorization becomes a major obstacle for the new architecture
منابع مشابه
Modeling Authorization in Enterprise-wide Contexts
Authorization and its enforcement, access control, has stood at the beginning of the art and science of information security, and remains being a crucial pillar of secure operation of IT. Dozens of different models of access control have been proposed. Although enterprise architecture as a discipline strives to support the management of IT, support for modeling authorization in enterprises is l...
متن کاملRole-Based Privilege Management Using Attribute Certificates and Delegation
The Internet provides tremendous connectivity and immense information sharing capability which the organizations can use for their competitive advantage. However, we still observe security challenges in Internet-based applications that demand a unified mechanism for both managing the authentication of users across enterprises and implementing business rules for determining user access to enterp...
متن کاملA Stateless Network Architecture for Inter-Enterprise Authentication, Authorization and Accounting
Providing network infrastructure for authenti-cation, authorization and accounting (AAA) functionalities required by inter-enterprise business applications operating over the global Internet is a challenging problem. The infrastructure needs to support large numbers of clients and services, and also to provide secure resources sharing between applications and across organizations. This paper de...
متن کاملA Distributed Architecture for Certificate-Based Delegation of Business Process Accessibility in Virtual Organizations
In this paper, a distributed architecture has been proposed in order to support an authorization service more precisely in dynamically created Virtual Organizations (VO). In comparison with other existing architectures such as Akenti, VOMS and TAS, our architecture uses certificates on top of the distributed agent architecture for managing requested resources among the VOs. The most obscure iss...
متن کاملAuthorization models for secure information sharing: a survey and research agenda
This article presents a survey of authorization models and considers their 'fitness-for-purpose' in facilitating information sharing. Network-supported information sharing is an important technical capability that underpins collaboration in support of dynamic and unpredictable activities such as emergency response, national security, infrastructure protection, supply chain integration and emerg...
متن کامل