首页> 外文会议>Information systems security >Authorization Policy Specification and Enforcement for Group-Centric Secure Information Sharing
【24h】

Authorization Policy Specification and Enforcement for Group-Centric Secure Information Sharing

机译:以组为中心的安全信息共享的授权策略规范和实施

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we propose a methodology for incremental security pol icy specification at varying levels of abstraction while maintaining strict equiv alence with respect to authorization state. We specifically consider the recently proposed group-centric secure information sharing (g-SIS) domain. The current specification for g-SIS authorization policy is stateless in the sense that it solely focuses on specifying the precise conditions under which authorization can hold in the system while only considering the history of actions that have occurred. The stateless application policy has been specified using linear temporal logic. In this paper, we develop an enforceable specification that is stateful in the sense that it is defined using specific data structures that are maintained in each state so as to make authorization decisions. We show that the stateful specification is authorization equivalent to that of stateless. That is, in any state, authorization will hold in stateful if and only if it also holds in the stateless specification.
机译:在本文中,我们提出了一种在不同抽象级别上进行增量安全策略规范的方法,同时在授权状态方面保持了严格的对等。我们专门考虑最近提出的以组为中心的安全信息共享(g-SIS)域。当前的g-SIS授权策略规范是无状态的,因为它仅关注于指定可以在系统中保留授权的精确条件,而仅考虑已发生的操作的历史记录。已使用线性时序逻辑指定了无状态应用程序策略。在本文中,我们开发了一个可执行的规范,该规范是有状态的,在某种意义上说,它是使用在每种状态下维护的特定数据结构定义的,以便做出授权决策。我们证明了有状态规范是等同于无状态规范的授权。也就是说,在任何状态下,当且仅当授权也包含在无状态规范中时,授权才会处于有状态。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号