首页> 外文会议>Information Systems Security; Lecture Notes in Computer Science; 4332 >Specification and Realization of Access Control in SPKI/SDSI
【24h】

Specification and Realization of Access Control in SPKI/SDSI

机译:SPKI / SDSI中访问控制的规范和实现

获取原文
获取原文并翻译 | 示例

摘要

SACL is an access control language based on SPKI/SDSI PKI that has features like group certificates, delegation, threshold certificates etc. In this paper, we show how SACL can be effectively realized in a Security Automata framework. We establish the equivalence of the transformation with the SPKI/SDSI semantics as well as the set-theoretic semantics. The transformation gives an efficient way to enforce the policy being defined and allows inference of authorizations obtained from multiple certificates. Further, we describe algorithms for efficiently solving certificate-analysis problems, resource authentication problems etc. The transformation allows us to capture the authorization of tags while being delegated in an unambiguous way and, define the set of tags permissible under threshold certification. The framework succinctly captures the expressive power of SACL and enables heterogenous integration of SACL with state-based security mechanisms that are widely used for protection/security of classical OS, Databases etc. One of the distinct advantages of the framework is the amenability of using finite state model-checking algorithms for verifying access control. We shall show how very useful properties can be verified using our transformation.
机译:SACL是一种基于SPKI / SDSI PKI的访问控制语言,具有组证书,委派,阈值证书等功能。在本文中,我们展示了如何在Security Automata框架中有效地实现SACL。我们用SPKI / SDSI语义以及集合理论语义建立转换的等价关系。该转换提供了一种有效的方法来实施所定义的策略,并允许推断从多个证书获得的授权。此外,我们描述了可有效解决证书分析问题,资源认证问题等的算法。该转换使我们能够以明确的方式委派标签的同时捕获标签的授权,并定义阈值证书下允许的标签集。该框架简洁地捕获了SACL的表达能力,并使SACL与基于状态的安全机制进行异构集成,该机制广泛用于经典OS,数据库等的保护/安全。该框架的显着优势之一是可以使用有限的状态模型检查算法以验证访问控制。我们将展示如何使用我们的转换来验证非常有用的属性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号