首页> 外文会议>Computer security-ESORICS 2008 >On the Security of Delegation in Access Control Systems
【24h】

On the Security of Delegation in Access Control Systems

机译:关于访问控制系统中委派的安全性

获取原文
获取原文并翻译 | 示例

摘要

Delegation is a mechanism that allows a user A to act on another user B's behalf by making B's access rights available to A. It is well recognized as an important mechanism to provide resiliency and flexibility in access control systems, and has gained popularity in the research community. However, most existing literature focuses on modeling and managing delegations. Little work has been done on understanding the impact of delegation on the security of existing access control systems. In particular, no formal notion of security with respect to delegation has been proposed. Many existing access control systems are designed without having delegation in mind. Simply incorporating a delegation module into those systems may cause security breaches.rnThis paper focuses on the security aspect of delegation in access control systems. We first give examples on how colluding users may abuse the delegation support of access control systems to circumvent security policies, such as separation of duty. As a major contribution, we propose a formal notion of security with respect to delegation in access control systems. After that, we discuss potential mechanisms to enforce security. In particular, we design a novel source-based enforcement mechanism for workflow authorization systems so as to achieve both security and efficiency.
机译:委派是一种机制,它允许用户A通过将B的访问权限提供给A来代表另一个用户B。它是公认的在访问控制系统中提供弹性和灵活性的重要机制,并且在研究中广受欢迎。社区。但是,大多数现有文献集中在对委托进行建模和管理上。在了解委托对现有访问控制系统的安全性的影响方面所做的工作很少。特别是,没有提出关于授权的正式安全概念。许多现有的访问控制系统在设计时都没有考虑到委派。将委派模块简单地集成到那些系统中可能会导致安全漏洞。本文重点讨论访问控制系统中委派的安全性。我们首先给出示例,说明合谋用户可能如何滥用访问控制系统的委托支持来规避安全策略,例如职责分离。作为一项重要的贡献,我们提出了关于访问控制系统中委派的正式安全概念。之后,我们讨论了强制执行安全性的潜在机制。特别是,我们为工作流授权系统设计了一种基于源的新颖执行机制,以实现安全性和效率。

著录项

  • 来源
    《Computer security-ESORICS 2008》|2008年|317-332|共16页
  • 会议地点 Malaga(ES);Malaga(ES)
  • 作者单位

    Department of Computer Science, Purdue University;

    Department of Computer Science, Purdue University;

    Department of Computer Science, Purdue University;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 安全保密;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号