【24h】

Comparing the Expressive Power of Access Control Models

机译:比较访问控制模型的表现力

获取原文
获取原文并翻译 | 示例

摘要

Comparing the expressive power of access control models is recognized as a fundamental problem in computer security. Such comparisons are generally based on simulations between different access control schemes. However, the definitions for simulations that are used in the literature make it impossible to put results and claims about the expressive power of access control models into a single context and to compare such models to one another in a meaningful way. We propose a theory for comparing the expressive power of access control models. We perceive access control systems as state-transition systems and require simulations to preserve security properties. We discuss the rationale behind such a theory, apply the theory to reexamine some existing work on the expressive power of access control models in the literature and present three results. We show that: (1) RBAC with a particular administrative model from the literature (ARBAC97) is limited in its expressive power; (2) ATAM (Augmented Typed Access Matrix) is more expressive than TAM (Typed Access Matrix), thereby solving an open problem posed in the literature; and (3) a trust-management language is at least as expressive as RBAC with a particular administrative model (the URA97 component of ARBAC97).
机译:比较访问控制模型的表达能力被认为是计算机安全性的基本问题。此类比较通常基于不同访问控制方案之间的仿真。但是,文献中使用的模拟定义使得不可能将有关访问控制模型的表达能力的结果和主张放在一个单一的上下文中,并且无法以有意义的方式将这些模型相互比较。我们提出了一种用于比较访问控制模型的表达能力的理论。我们将访问控制系统视为状态转换系统,并需要进行仿真以保留安全性。我们讨论了这种理论的基本原理,将其应用到文献中有关访问控制模型的表达能力的现有工作上进行了重新审查,并给出了三​​个结果。我们证明:(1)RBAC具有来自文献(ARBAC97)的特定管理模型,其表达能力受到限制; (2)ATAM(增强型访问矩阵)比TAM(型访问矩阵)更具表现力,从而解决了文献中提出的开放性问题; (3)信任管理语言至少与RBAC一样具有特定的管理模型(ARBAC97的URA97组件)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号