Download D3.3.1 eAuthorisation architecture and platform
Transcript
FP7-ICT 611659 AU2EU 3 Deliverable D3.3.1 Context and challenges Multiple parties may need to collaborate. A difficult challenge is to conciliate the different affiliations to security domains, the authorities that govern them and the distributed nature of the system. When an initial trust level is established, and a decision to join a collaboration is made, authorization processes pose the first challenge. Beyond the problems related to regulation of access to information, and the guarantee of confidentiality of information, the biggest challenge is the existence of different concepts and strategies to describe access control policies in the various participating organizations. Attributes (roles, identity attributes, resources attributes) that are utilized in access control policies differ from one organization to another, and there is no standard on sharing of access control policies. This problem is illustrated in Error! Reference source not found.. Figure 1 Need of mapping of authorization concepts Therefore, there is a need for mechanisms that can align different roles and attributes that are locally used in access control policies by organizations, to define equivalences across domains when needed. Another set of problems that occur when multiple organizations collaborate are that access control policies are not easily understandable, their effect is not always predictable, and conflicts in authorization decision over shared resources may occur due to different interests of the involved parties. The next challenge occurs after taking a decision to join the collaboration: the authentication process. Traditional authorization systems require all of the users’ information that may be relevant to an authorization decision. Consequently, the authentication components need to fully identify the users, and to collect all available information about them. This negates any privacy and security benefits of dataminimization authentication technologies, such as private credential systems. Credential protection is an important requirement of the AU2EU pilots. However, there is a high complexity in the implementation and integration of privacy-preserving authentication techniques into existing authorization systems. D3.1.1 describes the design and the principle of the mechanisms for mapping authorization attributes in a multi-organizational context. The document describes a mapping solution that is structured on a common base ontology, alignment between domain vocabulary of different organizations to this base ontology, and an ontology conversion service, which dynamically converts authorization attributes of different organizations. In addition, D3.1.1 analyses ontology verification tools, describes a logicJanuary 7, 2015 eAuthorization Architecture and Platform Implementation 12