首页> 外文会议>Computer security-ESORICS 2009 >Dynamic Enforcement of Abstract Separation of Duty Constraints
【24h】

Dynamic Enforcement of Abstract Separation of Duty Constraints

机译:职责限制抽象分离的动态实施

获取原文
获取原文并翻译 | 示例

摘要

Separation of Duties (SoD) aims to prevent fraud and errors by distributing tasks and associated privileges among multiple users. Li and Wang proposed an algebra (SoDA) for specifying SoD requirements, which is both expressive in the requirements it formalizes and abstract in that it is not bound to any specific workflow model. In this paper, we both generalize SoDA and map it to enforcement mechanisms. First, we increase SoDA's expressiveness by extending its semantics to multisets. This better suits policy enforcement over workflows, where users may execute multiple tasks. Second, we further generalize SoDA to allow for changing role assignments. This lifts the strong restriction that authorizations do not change during workflow execution. Finally, we map SoDA terms to CSP processes, taking advantage of CSP's operational semantics to provide the critical link between abstract specifications of SoD requirements by SoDA terms and runtime-enforcement mechanisms.
机译:职责分离(SoD)旨在通过在多个用户之间分配任务和相关特权来防止欺诈和错误。 Li和Wang提出了一个用于指定SoD需求的代数(SoDA),该代数在形式化的需求中具有表达性,并且抽象化了,因为它不受任何特定的工作流程模型的约束。在本文中,我们既概括了SoDA并将其映射到执行机制。首先,我们通过将SoDA的语义扩展到多集合来提高其表达能力。这更适合在用户可以执行多个任务的工作流上实施策略。其次,我们进一步推广SoDA,以允许更改角色分配。这解除了严格的限制,即在工作流程执行期间授权不会更改。最后,我们利用CSP的操作语义将SoDA术语映射到CSP流程,以提供SoDA术语对SoD要求的抽象规范与运行时执行机制之间的关键链接。

著录项

  • 来源
    《Computer security-ESORICS 2009》|2009年|250-267|共18页
  • 会议地点 Saint-Malo(FR);Saint-Malo(FR)
  • 作者单位

    ETH Zurich, Department of Computer Science, Switzerland;

    ETH Zurich, Department of Computer Science, Switzerland IBM Research, Zurich Research Laboratory, Switzerland;

    IBM Research, Zurich Research Laboratory, Switzerland;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 安全保密;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号