Sécurité des ressources collaboratives dans les réseaux sociaux d'entreprise. (Security of collaborative resources in enterprises social networks)

نویسنده

  • Ahmed Bouchami
چکیده

Enterprise social networks (ESN) have revolutionized collaboration between professional organizations. By means of an ESN, conventional mobility constraints, complex procedures for services exchange and the lack of flexibility and communication are no longer concerns. In this thesis we have worked on the project OpenPaaS ESN. Mainly we focused on the management of the access control, which led us to other needs, namely the management of digital identities and their monitoring. We worked primarily on managing the authentication of digital identities within collaborative communities made of heterogeneous enterprises regarding authentication management systems. For this, we have proposed an interoperable architecture for managing federated authentication, allowing thus each enterprise to preserve its (own) authentication mechanism and each principal to perform a single sign on authentication regarding different enterprises. Further, we focused on the management of digital identities accreditations, i.e. Access Control. On this aspect, we have proposed a flexible access control model based on a set of identity attributes. We developed this model on the basis of a formal language based on temporal logic, namely the Event-Calculus logic. We were thus able to make the sharing of resources fluid and agile, and also able to handle temporary authorizations, i.e. delegations. The fluidity and agility of the shares is due to the user-centric resources’ sharing in a straightforward manner. In addition, the logical formalism has allowed us to automatically check the access control policies consistency. For enterprises, our access control system gives them the ability to control the user-centric sharing policies through policies based on a risk management mechanism, which make our access control mechanism dynamic. The risk mechanism is based on the NIST’s risk definition with an alignment with a set of parameters that include access control in the ESN context. More precisely, the dynamic risk management includes, the collaborative resource’s importance, the authentication system’s vulnerabilities and trust level reflected through the behavior of each collaborative actor. On this latter aspect of trust, we made an evaluation of trust through the computation of reputation scores based on the history of collaborative interactions of each subject of collaboration. Finally, we have implemented all those security modules and integrate them as a prototype into OpenPaaS ESN.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Contextualizations in a Social Network. Context in Social networks and virtual communities

This paper proposes a context-based approach of social networks and virtual communities in the enterprise area. We point out that making context explicit it is possible to provide a global picture of the main aspects of social networks. A first result of this study is that the explicit consideration of contexts—especially shared contexts—could improve notably the collaborative-work processes in...

متن کامل

Detecting and Excluding Misbehaving Nodes in a P2P Network

Given their fully distributed architecture, P2P networks allow the design of low cost and high availability systems but also pose new security problems. In these collaborative networks, security properties need to be ensured by the participants themselves. In this paper, we propose to detect and exclude misbehaving nodes to allow honest participants to enforce security properties. The proposed ...

متن کامل

Impact des Réseaux Sociaux sur le Processus de Recherche d'Information

RÉSUMÉ. L'explosion du Web 2.0 (blogs, wikis, sites de partage, réseaux sociaux, etc.) ouvre des perspectives inédites de partage et de gestion de l'information, en permettant la construction collaborative de contenus et le développement de réseaux sociaux ouverts. Notre travail s'articule autour des problématiques d'accès à l'information dans ce contexte où l'utilisateur est à la fois producte...

متن کامل

Un Modèle de Diffusion de l'Information dans les Réseaux Sociaux

Résumé. Les réseaux sociaux sont un outil que les gens utilisent de plus en plus pour communiquer et partager de l’information. Un certain nombre d’études ont été effectuées, sur les réseaux sociaux, la propagation de l’innovation et les maladies afin de comprendre et de modéliser la diffusion dans des graphes d’utilisateurs. Dans un premier temps, nous présentons ici un modèle de diffusion de ...

متن کامل

Study and Development of a Symmetric protocol to secure communications in WSN

Résumé : Durant cette dernière décennie, les réseaux de capteurs sans fil (RCSF) ont attiré l’attention des chercheurs et des services de recherche et développement en raison de leur facilité de déploiement et de leur champs d’application dans divers domaines, y compris la sécurité et la surveillance, le contrôle, la maintenance des systèmes complexes, l’agriculture, e-santé, etc. Toutefois, en...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016