Sinnott R O, Doherty T, Gray N, Lusted J
National e-Science Centre, University of Glasgow, UK.
Stud Health Technol Inform. 2009;147:201-11.
Collaborative research can often have demands on finer-grained security that go beyond the authentication-only paradigm as typified by many e-Infrastructure/Grid based solutions. Supporting finer-grained access control is often essential for domains where the specification and subsequent enforcement of authorization policies is needed. The clinical domain is one area in particular where this is so. However it is the case that existing security authorization solutions are fragile, inflexible and difficult to establish and maintain. As a result they often do not meet the needs of real world collaborations where robustness and flexibility of policy specification and enforcement, and ease of maintenance are essential. In this paper we present results of the JISC funded Advanced Grid Authorisation through Semantic Technologies (AGAST) project (www.nesc.ac.uk/hub/projects/agast) and show how semantic-based approaches to security policy specification and enforcement can address many of the limitations with existing security solutions. These are demonstrated into the clinical trials domain through the MRC funded Virtual Organisations for Trials and Epidemiological Studies (VOTES) project (www.nesc.ac.uk/hub/projects/votes) and the epidemiological domain through the JISC funded SeeGEO project (www.nesc.ac.uk/hub/projects/seegeo).
合作研究通常对细粒度安全有要求,这种要求超出了许多基于电子基础设施/网格的解决方案所代表的仅认证范式。对于需要规范和随后执行授权策略的领域,支持细粒度访问控制通常至关重要。临床领域尤其如此。然而,现有安全授权解决方案脆弱、不灵活且难以建立和维护。因此,它们往往无法满足现实世界合作的需求,在这些合作中,策略规范和执行的稳健性与灵活性以及易于维护至关重要。在本文中,我们展示了由英国联合信息系统委员会(JISC)资助的通过语义技术实现高级网格授权(AGAST)项目(www.nesc.ac.uk/hub/projects/agast)的成果,并展示了基于语义的安全策略规范和执行方法如何能够解决现有安全解决方案的许多局限性。这些通过由医学研究理事会(MRC)资助的试验与流行病学研究虚拟组织(VOTES)项目(www.nesc.ac.uk/hub/projects/votes)在临床试验领域以及通过由JISC资助的SeeGEO项目(www.nesc.ac.uk/hub/projects/seegeo)在流行病学领域得到了证明。