首页> 外文会议>Functional and constraint logic programming >Types for Role-Based Access Control of Dynamic Web Data
【24h】

Types for Role-Based Access Control of Dynamic Web Data

机译:动态Web数据基于角色的访问控制的类型

获取原文
获取原文并翻译 | 示例

摘要

We introduce a role-based access control calculus for modelling dynamic web data and a corresponding type system. It is an extension of the XdTT calculus proposed by Gardner and Maffeis. In our framework, a network is a parallel composition of locations, where each location contains processes with roles and a data tree whose edges are associated with roles. Processes can communicate, migrate from a location to another, use the data, change the data and the roles in the local tree. In this way, we obtain a model that controls process access to data. We propose a type system which ensures that a specified network policy is respected during computations. Finally, we show that our calculus obeys the following security properties: (1) all data trees and processes with roles in a location agree with the location policy; (2) a process can migrate only to a location with whose policy it agrees; (3) a process with roles can read and modify only data which are accessible to it; (4) a process with roles can enable and disable roles in agreement with the location policy.
机译:我们介绍了基于角色的访问控制演算,用于对动态Web数据和相应的类型系统进行建模。它是Gardner和Maffeis提出的XdTT演算的扩展。在我们的框架中,网络是位置的并行组成,其中每个位置都包含具有角色的进程以及边缘与角色相关联的数据树。流程可以进行通信,从一个位置迁移到另一个位置,使用数据,更改数据和本地树中的角色。这样,我们获得了一个控制流程对数据访问的模型。我们提出一种类型系统,以确保在计算过程中遵守指定的网络策略。最后,我们证明了演算遵循以下安全属性:(1)在位置中具有角色的所有数据树和进程均与位置策略一致; (2)流程只能迁移到其策略同意的位置; (3)具有角色的流程只能读取和修改可访问的数据; (4)具有角色的进程可以根据位置策略启用和禁用角色。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号