首页> 外文会议> >Uniform application-level access control enforcement of organizationwide policies
【24h】

Uniform application-level access control enforcement of organizationwide policies

机译:组织范围策略的统一应用程序级访问控制实施

获取原文

摘要

Fine-grained and expressive access control policies on application resources need to be enforced in application-level code. Uniformly enforcing a single policy (referred to as the organizationwide policy) in diverse applications is challenging with current technologies. This is due to a poor delimitation of the responsibilities of application deployer and security officer, which hampers a centralized management of a policy and therefore compromises the uniformity of its enforcement. To address this problem, the concept of an access interface is introduced as a contract between an organization-wide authorization engine and the various applications that need its services. The access interface provides support for the central management of the policy by the security officer. By means of a view connector, the application deployer ensures that each application complies with this contract, so that the policy can be enforced.
机译:需要在应用程序级代码中实施对应用程序资源的细粒度和表达性的访问控制策略。在当前的技术中,在不同的应用程序中统一执行单个策略(称为组织范围的策略)是具有挑战性的。这是由于对应用程序部署者和安全员的职责划分不佳,这妨碍了对策略的集中管理,因此损害了其执行的统一性。为了解决此问题,将访问接口的概念作为组织范围的授权引擎与需要其服务的各种应用程序之间的契约而引入。访问界面为安全员对策略的集中管理提供支持。通过视图连接器,应用程序部署者确保每个应用程序都遵守该合同,以便可以执行该策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号