首页> 外文会议> >Formal authorization allocation approaches for role-based access control based on relational algebra operations
【24h】

Formal authorization allocation approaches for role-based access control based on relational algebra operations

机译:基于关系代数运算的基于角色的访问控制的正式授权分配方法

获取原文

摘要

We develop formal authorization allocation algorithms for role-based access control (RBAC). The formal approaches are based on relational structure, and relational algebra and operations. The process of user-role assignments is an important issue in RBAC because it may modify the authorization level or imply high-level confidential information to be derived while users change positions and request different roles. There are two types of problems which may arise in user-role assignment. One is related to the authorization granting process. When a role is granted to a user this role may conflict with other roles of the user or together with this role; the user may have or derive a high level of authority. Another is related to authorization revocation. When a role is revoked from a user, the user may still have the role from other roles. To solve these problems, this paper presents an authorization granting algorithm, and weak revocation and strong revocation algorithms that are based on relational algebra. The algorithms can be used to check conflicts and therefore to help allocate roles without compromising the security in RBAC. We describe how to use the new algorithms with an anonymity scalable payment scheme. Finally, comparisons with other related work are discussed.
机译:我们开发了基于角色的访问控制(RBAC)的正式授权分配算法。形式化方法基于关系结构,关系代数和运算。用户角色分配过程是RBAC中的一个重要问题,因为它可能会修改授权级别或暗示在用户更改职位和请求不同角色时要派生的高级机密信息。用户角色分配中可能会出现两种类型的问题。一个与授权授予过程有关。将角色授予用户后,此角色可能会与用户的其他角色发生冲突,或者与此角色一起发生冲突。用户可能具有或获得较高的权限。另一个与授权撤销有关。从用户撤消一个角色后,该用户可能仍然具有其他角色的角色。为了解决这些问题,本文提出了一种基于关系代数的授权授予算法,弱撤销和强撤销算法。该算法可用于检查冲突,从而帮助分配角色而不会影响RBAC中的安全性。我们描述了如何将新算法与匿名可扩展支付方案一起使用。最后,讨论了与其他相关工作的比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号