Structuring the Scope: Enabling Adaptive and Multilateral Authorization Management
Authors/Creators
- 1. Graz University of Technology
Description
In this work, we examine an access scope, a concept in authorization management broadly applied for the specification of access constraints in web service integrations. By analyzing a typical use-case of cross-organizational cloud service automation, we show the suboptimal capabilities of static, coarse-grained and inflexible scopes that negatively impact security and management of service integrations on a web scale. Using the graph-based structure that relies on semantic technologies we introduce dereferenceable and selfdescriptive authorization extents that allow expressive, granular and dynamic specification of security requirements. Through its application in the running scenario, we show how this construct can be administered to support
confidentiality, integrity and privacy requirements of service integrations by allowing selective information sharing based on contextual properties.