Fine-grained information access in Virtual Organisations

F. Hilbert,P. Katranuschkov,R. Scherer
2010-10-01
Abstract:Virtual organisations (VOs) in construction are highly dynamic in their composition and operability. Typically, information processing in such VOs takes place on a virtual platform which regulates the access of the VO members (subjects) to the digital information resources (objects) representing dynamic real-world subjects and objects. Their context information reflecting the current situation and viable to changes during processing is mapped to a context model. The selection of authorized operations may therefore depend on the actual status of this context model. Hence it is important to include the context model in authorization decisions to achieve a highly flexible authorization mechanism capable of handling the dynamics of Virtual Organisations. In addition, access can be restricted to parts of an object. However, current access control approaches based on the standard RBAC model or the extended ABAC model are still largely static, lacking the necessary dynamicity, flexibility and fine granularity required by construction VOs. In this paper we describe an approach for the realization of fine-grained context-aware access management, mapping the required dynamic VO behaviour in an ICT environment. With the help of a generic platform ontology acting as context model that describes the actors, resources and processes of a VO by combining features of the RBAC and ABAC models a fine-grained context-specific user support complemented with role-based business, access and representation profiles was achieved.
What problem does this paper attempt to address?