• Title/Summary/Keyword: Role-Based Access Control

Search Result 273, Processing Time 0.025 seconds

A Design of Role Based Access Control Manager in Distributed Virtual Environment (분산 가상 환경에서 역할 기반 접근 제어 관리자 설계)

  • Jung, Heon-Man;Tak, Jin-Hyun;Lee, Sei-Hoon;Wang, Chang-Jong
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2000.04a
    • /
    • pp.175-180
    • /
    • 2000
  • 분산 가상 환경은 고속 통신망과 컴퓨팅 환경의 고급화로 응용 분야를 넓혀 가고 있으며, 보다 현실감 있는 상호작용으로 인해 만남과 대화, 협력 작업, 상거래, 오락 등의 인간의 사회적 활동을 지원하는 새로운 수단으로 자리잡고 있다. 가상 도시와 같은 대규모의 가상 환경에는 공원이나 거리, 건물의 로비 등과 같은 개방적인 공간과 사무실과 같은 업무 공간, 그리고 쇼핑몰과 같은 상거래 공간들이 공존하게 되므로 접근 제어와 보안이 보다 중요한 문제로 대두된다. 따라서, 이 논문에서는 분산 가상 환경내의 모든 사물들을 객체로 인식하고, 객체에 대한 역할을 기반으로 하는 접근 제어 모델을 제안하고, 제안한 모델을 기반으로 접근 제어 관리자를 설계하였다. 설계된 접근 제어 관리자는 가상 환경내 공간의 객체 뿐만 아니라 공간 자체도 하나의 객체로 인식하여 접근 제어를 하였다. 또한, 대규모 공간에서의 중요한 특징인 관리의 용이성과 동적인 변경을 가능하게 하기 위해, 역할을 기반으로 참여자와 객체를 연결하고, 객체가 갖고 있는 행위까지를 제어할 수 있었다.

  • PDF

SPKI/SDSI HTTP Secure Server to support Role-based Access Control & Confidential Communication (역할기반 접근제어 및 비밀통신을 지원하는 SPKI/SDSI 보안 서버)

  • 이영록;김민수;김용민;노봉남;이형효
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.12 no.6
    • /
    • pp.29-46
    • /
    • 2002
  • We generally use SSL/TLS protocol utilizing X.509 v3 certificates so as to provide a secure means in establishment an confidential communication and the support of the authentication service. SPKI/SDSI was motivated by the perception that X.509 is too complex and incomplete. This thesis focuses on designing a secure server and an implementation of the prototype which has two main modules, one is to support secure communication and RBAC, not being remained in the SPKI/SDSI server which was developed by the existing Geronimo project and the other is to wholly issue name-certificate and authorization-cerificate. And the demonstration embodied for our sewer is outlined hereafter.

Role-Based Access Control and Key Management Scheme in Mobile Agent Environments (이동 에이전트 환경에서 역할 기반 접근 제어와 키 관리 기법)

  • Dongwoo Kim;Changhwan Song;Young Ik Eom
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2008.11a
    • /
    • pp.1513-1516
    • /
    • 2008
  • 이동 에이전트는 기존의 클라이언트-서버 환경을 대체하는 분산 컴퓨팅 패러다임이다. 특히 이동 에이전트는 목표를 달성할 때까지 스스로 인터넷 환경을 떠돌며 정보를 수집하고 분석할 수 있도록 설계할 수 있다. 하지만 이동 에이전트가 문제없이 활동하기에 인터넷은 개방적인 환경이며, 많은 경우에 있어 이동 에이전트는 여러 적대적인 호스트들과 접할 수 있다. 이로 인해 이동 에이전트가 안전하게 인터넷상에서 이주 하도록 만드는 것이 큰 관건이 되고 있다. 최근 Volker와 Mehrdad가 이동 에이전트 환경에 있어서 효율적인 접근 제어와 키 관리 메커니즘을 제안하였다. 하지만 이 기법은 이동 에이전트의 이주 대상을 한정시키고, 이주 대상이 많아질수록 키를 관리하는 구조가 커지는 문제점이 있다. 본 논문에서는 이동 에이전트에 역할 모델을 적용함으로써 키 관리에 있어서 그 크기를 줄이고, 인증 센터를 사용하여 이동 에이전트의 이주 대상 호스트를 미리 한정짓지 않도록 하여 이동 에이전트가 자유롭게 이주할 수 있는 접근제어 기법을 제안한다. 본 기법을 이동 에이전트에 적용하면 에이전트의 크기를 줄이고, 이동할 수 있는 호스트의 제약을 줄일 수 있다.

Physical Layer Diversity and its Effects on the Performance of WLANs (물리 계층의 다양성과 무선 랜의 성능에 미치는 영향)

  • Choi, Sunwoong;Park, Kihong;Kim, Chong-Kwon
    • Journal of KIISE:Information Networking
    • /
    • v.32 no.6
    • /
    • pp.723-731
    • /
    • 2005
  • Wide spread deployment of infrastructure WLANs has made Wi Fi an integral part of today's Internet access technology. Despite its crucial role in affecting end to end performance, past research has focused on MAC protocol enhancement, analysis and simulation based performance evaluation without sufficient consideration for modeling inaccuracies stemming from inter layer dependencies, including physical layer diversity, that significantly impact performance. We take a fresh look at IEEE 802.11 WLANs, and using experiment, simulation, and analysis demonstrate its surprisingly agile performance traits. Contention based MAC throughput degrades gracefully under congested conditions, enabled by physical layer channel diversity that reduces the effective level of MAC contention. In contrast, fairness and jitter significantly degrade at a critical offered load. This duality obviates the need for link layer flow control for throughput improvement but necessitates traffic control for fairness and QoS. We use experimentation and simulation in a complementary fashion, pointing out performance characteristics where they agree and differ.

A Study on Government Service Innovation with Intelligent(AI): Based on e-Government Website Assessment Data (전자정부 웹사이트 평가 결과 데이터 기반 지능형(AI) 정부 웹서비스 관리 방안 연구)

  • Lee, Eun Suk;Cha, Kyung Jin
    • Journal of Information Technology Services
    • /
    • v.20 no.2
    • /
    • pp.1-11
    • /
    • 2021
  • As a key of access to public participation and information, e-government is taking the active role of public service by relevant laws and policy measures for universal use of e-government websites. To improve the accessibility of web contents, the level of deriving the results for each detailed evaluation item according to the Korean web contents accessibility guideline is carried out, which is an important factor according to the detailed evaluation items for each website property and requires data-based management. In this paper, detailed indicators are analyzed based on the quality control level diagnosis results of existing domestic e-government websites, and the results are classified according to high and low to propose new improvement directions and induce detailed improvement. Depending on the necessity of management according to the detailed indicators for each website attribute, not only results but also level diagnosis to strengthen web service quality suggests directions for future improvement through accurate detailed analysis and research for policy feedback. This study ultimately makes it possible to expect government system management based on predicted data through deduction history management based on evaluation score data on public websites. And it provides several theoretical and practical implications through correlation and synergy. The characteristics of each score for the quality management of public sector websites were identified, and the accuracy of evaluation, the possibility of sophisticated analysis, such as analysis of characteristics of each institution, were expanded. With creating an environment for improving the quality of public websites and it is expected that the possibility of evaluation accuracy and elaborate analysis can be expanded in the e-government performance and the post-introduction stage of government website service.

Integrated Privacy Protection Model based on RBAC (RBAC에 기초한 통합형 프라이버시 보호 모델)

  • Cho, Hyug-Hyun;Park, Hee-Man;Lee, Young-Lok;Noh, Bong-Nam;Lee, Hyung-Hyo
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.20 no.4
    • /
    • pp.135-144
    • /
    • 2010
  • Privacy protection can only be achieved by enforcing privacy policies within an enterprise's on and offline data processing systems. There are P-RBAC model and purpose based model and obligations model among privacy policy models. But only these models each can not dynamically deal with the rapidly changing business environment. Even though users are in the same role, on occasion, secure system has to opt for a figure among them who is smart, capable and supremely confident and to give him/her a special mission during a given period and to strengthen privacy protection by permitting to present fluently access control conditions. For this, we propose Integrated Privacy Protection Model based on RBAC. Our model includes purpose model and P-RBAC and obligation model. And lastly, we define high level policy language model based XML to be independent of platforms and applications.

A Time Synchronization Algorithm for a Time-Slot Reservation Based MAC in Mobile Ad-Hoc Networks (모바일 애드혹 네트워크에서 MAC 기반 타임 슬롯 예약을 위한 시간 동기화 알고리즘)

  • Heo, Ung;He, Yushan;You, Kang-Soo;Choi, Jae-Ho
    • Journal of the Institute of Electronics Engineers of Korea TC
    • /
    • v.48 no.4
    • /
    • pp.37-46
    • /
    • 2011
  • Time synchronization plays an important role in mobile communication systems, particularly, when an accurate time-division mechanism among the communication entities is required. We present a new time synchronization algorithm for a wireless mobile ad-hoc network assuming that communication link is managed by a time-slot reservation-based medium access control protocol. The central idea is to reduce time synchronization packet collisions by exploiting the advantages found in reference broadcasting. In addition, we adopt a sophisticated clock updating scheme to ensure the time synchronization convergence. To verify the performance of our algorithm, a set of network simulations has been performed under various mobile ad-hoc network scenarios using the OPNET. The results obtained from the simulations show that the proposed method outperforms the conventional TSF method in terms of synchronization accuracy and convergence time.

A Joint Topology Discovery and Routing Protocol for Self-Organizing Hierarchical Ad Hoc Networks (자율구성 계층구조 애드혹 네트워크를 위한 상호 연동방식의 토폴로지 탐색 및 라우팅 프로토콜)

  • Yang Seomin;Lee Hyukjoon
    • The KIPS Transactions:PartC
    • /
    • v.11C no.7 s.96
    • /
    • pp.905-916
    • /
    • 2004
  • Self-organizing hierarchical ad hoc network (SOHAN) is a new ad-hoc network architecture designed to improve the scalability properties of conventional 'flat' ad hoc networks. This network architecture consists of three tiers of ad-hoc nodes, i.e.. access points, forwarding nodes and mobile nodes. This paper presents a topology discovery and routing protocol for the self-organization of SOHAN. We propose a cross-layer path metric based on link quality and MAC delay which plays a key role in producing an optimal cluster-based hierarchical topology with high throughput capacity. The topology discovery protocol provides the basis for routing which takes place in layer 2.5 using MAC addresses. The routing protocol is based on AODV with appropriate modifications to take advantage of the hierarchical topology and interact with the discovery protocol. Simulation results are presented which show the improved performance as well as scalability properties of SOHAN in terms of through-put capacity, end-to-end delay, packet delivery ratio and control overhead.

Effects of Perceived Control on Usage Intention toward Digital Finance Service: Moderating Role of Privacy Concern (사용자의 지각된 통제력이 디지털 금융서비스 이용의도에 미치는 영향: 프라이버시 염려 조절효과를 중심으로)

  • Jun Mo Kang;Cheol Park
    • Information Systems Review
    • /
    • v.25 no.4
    • /
    • pp.161-181
    • /
    • 2023
  • As the post-COVID-19 consumer life environment is rapidly becoming non-face-to-face, changing non-face-to-face financial life services are having a significant impact on consumers' daily lives. People who do not have access to digital devices and services that have become essential goods are at risk of being left behind in the "digital blind spot," where they are marginalized not only in their daily lives but also in society and the economy as a whole (Kim Min-Jeung A, Kim Min-Jung B, Park Joo-Yung, 2022). In this study, we examined the effects of perceived control factors, Cognitive control, behavioral control, and decisional control, on intention to use digital finance. For this study, we surveyed 133 customers who are aware of and intend to use digital finance. The results show that cognitive control, behavioral control, and decisional control have significant effects on intention to use digital finance. In this relationship, the moderating effect of privacy concerns differs from the effect of decision control on intention to use digital finance. These findings suggest that digital financial services firms should consider whether to reduce or increase customer control. Based on these findings, we discuss marketing strategies and implications for digital financial services companies.

A Study on IPA-based Competitiveness Enhancement Measures for Regular Freight Service (IPA분석을 이용한 정기화물운송업의 경쟁력 강화방안에 관한 연구)

  • Lee, Young-Jae;Park, Soo-Hong;Sun, Il-Suck
    • Journal of Distribution Science
    • /
    • v.13 no.1
    • /
    • pp.83-91
    • /
    • 2015
  • Purpose - Despite the structural irrationality of multi-level transportation and the oil price rise, the domestic freight transportation market continues to grow, mirroring the rise in e-commerce and resultant increase in courier services and freight volumes. Several studies on courier services have been conducted. However, few studies or statistics have been published regarding regular freight services although they have played a role in the freight service market. The present study identifies the characteristics of regular freight service users to seek competitiveness enhancement measures specific to regular freight services. Research design, data, and methodology - IPA is a comparative analysis of the relative importance of and satisfaction with each attribute simultaneously. This study used IPA because it facilitates the process of analyzing importance and performance, deriving implications and a visual understanding of results. To enhance the competitiveness of regular freight services, this study surveyed its current users regarding the importance of the regular freight service factors. A total of 200 copies of a questionnaire were circulated and 190 copies were returned. In addition to demographics, respondents answered questions about the importance of and satisfaction with services on a 5-point Likert scale. Excluding 3 inappropriate copies, 187 out of 190 copies were analyzed. PASW Statistics 18 was used for statistical analysis. A total of 20 question items were selected for the service factors presented in the questionnaire based on the 1st pilot survey and previous studies. Results - According to the IPA performed to compare the importance of and satisfaction with service factors, both importance and satisfaction are high in the 1st quadrant, which involves the economic advantage of using regular freight services, quick arrival at destinations, weight freight handling, and less time constraints on freight receipt/dispatch. This area requires continuous management. Satisfaction is higher than importance in the 2nd quadrant, which involves the adequacy of freight, cost savings over ordinary courier services, notification on freight arrival, and freight tracking information. This area requires intensive investment and management. Satisfaction is lower than importance in the 3rd quadrant, involving the credit card payment system, courier delivery service, distance to freight handling sites, easy access to freight handling sites, and prompt problem solving. This area requires further intensive management. Both importance and satisfaction are low in the 4th quadrant, involving the availability of collection service, storage space at freight handling sites, kindness of collection/delivery staff, kindness of outlet staff, and easy delivery checks. This area is a set of variables should be excluded from priority control targets. Conclusions - Based on the IPA, service factors that need priority controls because of high importance and low satisfaction include the credit card payment system, delivery service, distance to freight handling sites, easy access to freight handling sites, and prompt problem solving. The findings need to be applied to future marketing strategies for regular freight services and for developing competitiveness enhancement programs.