首页> 外文会议>Computer Science and Network Technology (ICCSNT), 2011 International Conference on >Specification and enforcement of separation-of-duty policies in role-base access control
【24h】

Specification and enforcement of separation-of-duty policies in role-base access control

机译:角色库访问控制中职责分离策略的规范和实施

获取原文
获取原文并翻译 | 示例

摘要

Separation-of-duty (SoD) is widely considered to be a fundamental principle to role based access control (RBAC) models and systems should adhere. In this paper, we formulate and study the fundamental problem of SoD policies in the context of RBAC systems. We give a set-based specification of SoD policies and the safety checking problem for SoD policies in the context of RBAC. We study the problem of determining whether a SoD policy is enforceable, and show that directly enforcing SoD policies in RBAC is intractable (coNP-complete). Moreover, indirectly enforcing SoD policies by using mutually exclusive role constraints is also intractable (NP-hard). Therefore, we reduce the safety checking problem for SoD to SAT4J problem which can be solved using available SAT solvers. The experiments show the validity and effectively of the SAT approach.
机译:职责分离(SoD)被广泛认为是基于角色的访问控制(RBAC)模型和系统应遵循的基本原则。在本文中,我们在RBAC系统的背景下制定和研究SoD政策的基本问题。我们给出了基于集合的SoD策略规范以及在RBAC上下文中SoD策略的安全检查问题。我们研究了确定SoD策略是否可强制执行的问题,并显示了在RBAC中直接执行SoD策略是棘手的(coNP-complete)。此外,通过使用互斥角色约束来间接实施SoD策略也是很困难的(NP-hard)。因此,我们将SoD的安全检查问题简化为SAT4J问题,可以使用可用的SAT解算器来解决。实验证明了SAT方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号