首页> 外文会议>Information Security and Privacy >Advanced Permission-Role Relationship in Role-Based Access Control
【24h】

Advanced Permission-Role Relationship in Role-Based Access Control

机译:基于角色的访问控制中的高级权限角色关系

获取原文
获取原文并翻译 | 示例

摘要

Permission-role assignment is an important issue in role-based access control (RBAC). There are two types of problems that may arise in permission-role assignment. One is related to authorization granting process. Conflicting permissions may be granted to a role, and as a result, users with the role may have or derive a high level of authority. The other is related to authorization revocation. When a permission is revoked from a role, the role may still have the permission from other roles. In this paper, we discuss granting and revocation models related to mobile and immobile memberships between permissions and roles, then provide proposed authorization granting algorithm to check conflicts and help allocate the permissions without compromising the security. To our best knowledge, the new revocation models, local and global revocation, have not been studied before. The local and global revocation algorithms based on relational algebra and operations provide a rich variety. We also apply the new algorithms to an anonymity scalable payment scheme.
机译:权限角色分配是基于角色的访问控制(RBAC)中的重要问题。权限角色分配中可能会出现两种类型的问题。一涉及授权授予过程。可能会授予角色冲突的权限,因此,具有该角色的用户可能具有或获得较高的权限。另一个与授权吊销有关。从角色撤消权限后,该角色可能仍具有其他角色的许可。在本文中,我们讨论了权限和角色之间与移动和非移动成员资格相关的授予和撤消模型,然后提供了建议的授权授予算法来检查冲突并帮助在不损害安全性的情况下分配权限。据我们所知,以前尚未研究过新的撤销模型,即本地和全局撤销。基于关系代数和运算的局部和全局吊销算法提供了多种选择。我们还将新算法应用于匿名可扩展支付方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号