Published February 7, 2018 | Version v1

Structuring the Scope: Enabling Adaptive and Multilateral Authorization Management

  • 1. Graz University of Technology

Description

In this work, we examine an access scope, a concept in authorization management broadly applied for the specification of access constraints in web service integrations. By analyzing a typical use-case of cross-organizational cloud service automation, we show the suboptimal capabilities of static, coarse-grained and inflexible scopes that negatively impact security and management of service integrations on a web scale. Using the graph-based structure that relies on semantic technologies we introduce dereferenceable and selfdescriptive authorization extents that allow expressive, granular and dynamic specification of security requirements. Through its application in the running scenario, we show how this construct can be administered to support
confidentiality, integrity and privacy requirements of service integrations by allowing selective information sharing based on contextual properties.

Files

PID4962265-fin.pdf

Files (1.8 MB)

Name Size
md5:7fe6a70619dc29bcb09d4b2ae0049d8d
1.8 MB Preview Download

Additional details

Funding

European Commission
SUNFISH - SecUre iNFormation SHaring in federated heterogeneous private clouds 644666