Wang, Hua and Cao, Jinli and Zhang, Yanchun (2002) A flexible payment scheme and its user-role assignment. In: Cooperative internet computing. Springer (Kluwer Academic Publishers), pp. 107-128.
PDF (Accepted Version - Chapter 7)
A flexible payment scheme and its role-based user-role assignments are proposed in this paper. The scheme uses electronic cash for payment transactions. In this new protocol, from the viewpoint of banks, consumers can improve anonymity if they are worried about disclosure of their identities. A new role called anonymity provider agent (AP) provides a high anonymous certificate. The role AP certifies re-encrypted data after verifying the validity of the content from consumers, but with no private information of the consumers required. With this new method, each consumer can get a required anonymity level, depending on the available time, computation and cost. There are two types of problems that may arise in user-role assignments. One is related to authorization granting process. Mutually exclusive roles may be granted to a user and the user may have or derive a high level of authority. Another is related to authorization revocation. When a role is revoked from a user, the user may still have the role from other roles. To solve these problems, we first analyze the duty separation constraints of the roles and role hierarchies in the scheme, then discuss granting a role to a user, weak revocation and strong revocation for the scheme.
Statistics for this ePrint Item
|Item Type:||Book Chapter (Commonwealth Reporting Category B)|
|Item Status:||Live Archive|
|Additional Information:||Chapter 7. Accepted version deposited in accordance with the copyright policy of the publisher. Electronic version of book available via USQ Library catalogue.|
|Depositing User:||Dr Hua Wang|
|Faculty / Department / School:||Historic - Faculty of Sciences - Department of Maths and Computing|
|Date Deposited:||30 Mar 2011 07:44|
|Last Modified:||02 Jul 2013 23:58|
|Uncontrolled Keywords:||payment scheme, authorization, RBAC, AP agent|
|Fields of Research (FOR2008):||08 Information and Computing Sciences > 0806 Information Systems > 080608 Information Systems Development Methodologies|
Actions (login required)
|Archive Repository Staff Only|