...
首页> 外文期刊>International journal of computing & information technology >A UNIFORM CLAIMS-BASED ACCESS CONTROL FOR THE ENTERPRISE
【24h】

A UNIFORM CLAIMS-BASED ACCESS CONTROL FOR THE ENTERPRISE

机译:基于统一索赔的企业访问控制

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

When standing up a high-assurance, internet-scale, and web-service based enterprise system for information sharing, access control is a primary consideration. A generalized standards-based solution is presented. Central to this system is a process for access control that provides the fine-grained authorities for use by enterprise services. In all cases, the access control, rights and privileges are done by the web service itself, though its own Access Control Lists (ACLs), and are preceded by a bi-latera! authentication in both normal and federated service requests. The enterprise system relies on a unified naming and credentialing system for identity management which is not dealt with in this paper due to size constraints. This document provides the process by which access control and authorities' claims are developed at the enterprise level. The claims are computed using enterprise attributes, use cases, policy statements and other data together with an Attribute Based Access Control (ABAC) / Policy Based Access Control (PB AC) engine described in this paper. These claims are then placed in a Security Assertion Markup Language (SAML) token to be used by the web service. The SAML is signed for integrity and encrypted for confidentiality. This is the first enterprise level scale-up that has provided a consistent enterprise solution to access control that has not used a centralized Access Control Service and relies solely on the service for access control and authority determination.
机译:当建立一个高安全性,基于Internet规模和基于Web服务的企业系统进行信息共享时,访问控制是首要考虑因素。提出了一种基于标准的通用解决方案。该系统的中心是访问控制过程,该过程提供了供企业服务使用的细粒度权限。在所有情况下,访问控制,权限和特权都是由Web服务本身(尽管它具有自己的访问控制列表(ACL))来完成的,并且其前面是双向的!普通和联合服务请求中的身份验证。企业系统依赖用于身份管理的统一命名和证书系统,由于大小限制,本文未对其进行处理。本文档提供了在企业级别制定访问控制和权限声明的过程。使用企业属性,用例,策略声明和其他数据,以及本文所述的基于属性的访问控制(ABAC)/基于策略的访问控制(PB AC)引擎来计算索赔。然后,将这些声明放置在安全声明标记语言(SAML)令牌中,以供Web服务使用。 SAML经过签名以确保完整性,并经过加密以确保机密性。这是首次为访问控制提供一致的企业解决方案的企业级扩展,该解决方案没有使用集中式访问控制服务,仅依靠该服务来进行访问控制和权限确定。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号