【24h】

Relationship-Based Access Control for Online Social Networks: Beyond User-to-User Relationships

机译:在线社交网络基于关系的访问控制:超越用户到用户的关系

获取原文
获取原文并翻译 | 示例

摘要

User-to-user (U2U) relationship-based access control has become the most prevalent approach for modeling access control in online social networks (OSNs), where authorization is typically made by tracking the existence of a U2U relationship of particular type and/or depth between the accessing user and the resource owner. However, today's OSN applications allow various user activities that cannot be controlled by using U2U relationships alone. In this paper, we develop a relationship-based access control model for OSNs that incorporates not only U2U relationships but also user-to-resource (U2R) and resource-to-resource (R2R) relationships. Furthermore, while most access control proposals for OSNs only focus on controlling users' normal usage activities, our model also captures controls on users' administrative activities. Authorization policies are defined in terms of patterns of relationship paths on social graph and the hop count limits of these path. The proposed policy specification language features hop count skipping of resource-related relationships, allowing more flexibility and expressive power. We also provide simple specifications of conflict resolution policies to resolve possible conflicts among authorization policies.
机译:基于用户对用户(U2U)关系的访问控制已成为在线社交网络(OSN)中建模访问控制的最流行方法,其中授权通常是通过跟踪特定类型和/或特定类型的U2U关系的存在来进行的访问用户和资源所有者之间的深度。但是,当今的OSN应用程序允许各种用户活动,这些活动不能仅通过使用U2U关系来控制。在本文中,我们为OSN开发了一个基于关系的访问控制模型,该模型不仅包含U2U关系,而且还包含用户到资源(U2R)和资源到资源(R2R)关系。此外,尽管大多数针对OSN的访问控制建议仅集中于控制用户的正常使用活动,但我们的模型还捕获了对用户管理活动的控制。授权策略是根据社交图上的关系路径的模式以及这些路径的跳数限制来定义的。提出的策略规范语言具有与资源相关的关系的跳数跳过功能,从而具有更大的灵活性和表达能力。我们还提供了冲突解决策略的简单规范,以解决授权策略之间可能发生的冲突。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号