Abstract
Organizations deploy various types of access control systems for protecting their resources from unauthorized access. Choice of the underlying access control model is guided by the types of security policies required to be specified in individual organizations. Two of the most popular existing and upcoming ac- cess control models, namely, Role-based Access Control (RBAC) and Attribute-based Access Control (ABAC), in their basic forms can effectively enforce secure access to the resources of standalone organizations. However, recent growth in distributed operations of most organizations calls for an urgent need to collaborate for achieving collective goals through resource sharing. With dis- parate access control models deployed in different organizations or even in the subsidiaries of the same organization, such sharing presents an exigent situation. In this paper, we introduce the vision of a framework called Central Attribute Authority (CAA) that facilitates seamless sharing of organizational resources over heterogeneous access control models.