About Us Our Work Employment News & Events
MITRE Remote Access for MITRE Employees Site Map
Our Work
Share this page

Follow Us On:

Visit MITRE on Facebook
Visit MITRE on Twitter
Visit MITRE on YouTube
View MITRE's RSS Feeds
Home > Our Work > Technical Papers >

Scalable Access Controls for Lineage

May 2009

Arnon Rosenthal, The MITRE Corporation
Len Seligman, The MITRE Corporation
Adriane Chapman, The MITRE Corporation
Barbara Blaustein, The MITRE Corporation

ABSTRACT

Lineage stores often contain sensitive information that needs protection from unauthorized access. We build on prior work for security and privacy of lineage information, focusing on complex conditions and scalable administration. We use Attribute-Based Access Control (ABAC) to express conditions based on many attributes, instead of roles. We then make administration and management more scalable, instead of managing large, monolithic access predicates for each object. To do so, we first support modular traceability and maintainability for separate concerns (e.g. security, legally mandated privacy, organizationally mandated privacy). We then provide constructs to manage authority when multiple administrators must collaborate. We show that these security techniques are needed for easy lineage security administration.

» Download Paper [PDF, 911KB]

Additional Search Keywords

n/a

 

Page last updated: June 8, 2009   |   Top of page

Homeland Security Center Center for Enterprise Modernization Command, Control, Communications and Intelligence Center Center for Advanced Aviation System Development

 
 
 

Serving as Architects of Information Advantage.™
Copyright © 1997-2009, The MITRE Corporation. All rights reserved.
MITRE is a registered trademark of The MITRE Corporation.
Material on this site may be copied and distributed with permission only.

MITRE Named to FORTUNE's "100 Best Companies to Work For" List for Eighth Straight Year MITRE Named to "Best Places to Work in IT" List for Fifth Consecutive Year
 

Privacy Policy | Contact Us