Authors: Mariemma I. Yagüe ; Antonio Maña and Francisco Sánchez

Affiliation: Univ. of Malaga, E.T.S.I.Informatica, Spain

Abstract: The shift from paper documents to their respective electronic formats is producing important advantages in the functioning of businesses and Public Administrations. However, this shift is often limited to the internal operation of each entity because of the lack of security in the electronic communication mechanisms. Traditionally, these entities have managed their Local Area Networks (LANs) or even Virtual Private Networks (VPN) as isolated islands, where local identity-based authorization schemes were appropriate. But, the trend towards paperless procedures leads to the need for these entities to interoperate. As an advance, extranets were proposed to connect entities that share common goals in a way that automates their administrative interactions using Internet technology. However, the limited authorization and access control capabilities provided by extranets is a mayor drawback for their application in open and heterogeneous scenarios. Trust appears as the main issue to address in order to achieve secure interoperation of different independent entities. This paper presents a solution to this problem, based on the use of Privilege Management Infrastructures (PMIs) and the semantic description of the different authorization entities. (More)


I. Yagüe, M.; Maña, A. and Sánchez, F. (2004). Semantic Interoperability of Authorizations. In Proceedings of the 2nd International Workshop on Security in Information Systems - WOSIS, (ICEIS 2004) ISBN 972-8865-07-4, pages 269-278. DOI: 10.5220/0002682402690278

