An access control framework is responsible for efficiently and effectively managing an organization's resources on which its users can perform actions. Depending upon their requirements, different organizations deploy different kinds of access control frameworks. For a common goal, organizations often collaborate by contributing their resources and users. To integrate each other's resources and users, their access control frameworks should be interoperable. To help a collaboration realize, several models [14,41,42] exist. These models facilitate the collaboration among homogeneous access control frameworks. In practice, collaborators may have heterogeneous frameworks that may not share any similarity in their security orderings [10] which may prove to be a serious hitch for integrating each others' resources and users at an appropriate order. Here, we present a utility that allows one to form an overlay of definitions specific to the collaboration. Such definitions map new names for the existing definitions available within the framework. Thus, the new security order formed through overlay definitions can be presented as an interoperation interface to the collaborators. The use of overlays hides the internal security ordering of an organization from its collaborators and we shall see how collaboration specific context information can be captured and used in our approach. The post-collaboration setup should provide an efficient mechanism for authentication-cum-authorization of participants consistent with the local policies and ensure non-repudiation of any inter-organization communication. We have come across a cryptographic primitive, called chameleon hash, that has allowed us to efficiently realize the above mentioned requirements and properties. A preliminary analysis of our approach shows an advantage over existing certificate based practices [11,15,20,24,43] in terms of manageability, privacy and communication overheads. Our scheme should be the best implementation choice for dynamic and ephemeral collaborations where preserving pre-collaboration functional setup during the span of collaboration and also after the collaboration is important . Actually, this is a pressing need for organizations coping with globalization.In this paper, our goal is to devise an enforcement mechanism to facilitate concurrent collaborations in a distributed environment with a focus on the manageability, interoperability and privacy of collaborators. Privacy to the collaborators is a new unique feature provided under our approach.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.