A generalized model for internet-based access control systems with delegation support
Conference proceedings article
Authors/Editors
Strategic Research Themes
No matching items found.
Publication Details
Author list: Buranasaksee U., Porkaew K., Supasitthimethee U.
Publisher: Springer Verlag
Publication year: 2013
Volume number: 115
Start page: 975
End page: 988
Number of pages: 14
ISBN: 9783642379482
ISSN: 1867-8211
eISSN: 1867-8211
Languages: English-Great Britain (EN-GB)
Abstract
In the web environment, web browsers use HTTP/HTTPS to communicate between users and web/application servers. However, many internet activities require interactions among three parties without compromising confidentiality. For example, an e-commerce transaction requires a buyer to authorize an ecommerce website to withdraw money from the buyer’s bank account at an internet banking website. Although several existing works have been proposed to solve this problem, they are done in ad-hoc manners or lack of some important properties. This paper proposes a model, called PRA (Provider-Requestor- Authorizer), for generalizing three-party communication in the web-environment in order to identify desirable properties that can be used to measure the goodness of protocols for and classify them. We found that PRA model can generalize three-party communication protocols to a single model from conceptual level to implementation level. © Institute for Computer Sciences, Social Informatics and Telecommunications Engineering 2013.
Keywords
Delegation, Design, Distributed access control, Distributed system, Implementation