Tongxin xuebao (Jan 2008)
R~2BAC:a risk-based multi-domain secure interoperation model
Abstract
R2BAC,a risk enabled role—based model for multi-domain secure interoperation,was proposed to adapt to the dynamics of distributed environments.R2BAC employs a flexible mechanism to establish interoperation between domains,eliminating the need of a trusted third-party.It translates the problem of interoperation establishment into an op-timality problem,thus achieving optimal interoperability on the premise of domains’ security.The creation and abolish-ment of interoperation relationships in R2BAC are in accord with the dynamics of distributed environments,where do-mains join and leave in an ad hoc manner.Furthermore,R2BAC incorporates risk management methods,leading to at least two advantages.First,a fine-grained authorization mechanism is enabled;second,it is possible to monitor users’ behaviors and adjust their permission sets in a real time manner.