首页> 外文会议> >Apply Model Checking to Security Analysis in Trust Management
【24h】

Apply Model Checking to Security Analysis in Trust Management

机译:将模型检查应用于信任管理中的安全性分析

获取原文

摘要

Trust management is a form of access control that uses delegation to achieve scalability beyond a single organization or federation. However, delegation can be difficult to control. A resource owner that delegates some authority is naturally concerned not only about who has access today, but also who will have access after others make changes to the global policy state. They need tools to help answer such questions. This problem has been studied in the case of a trust management language called RT, where, for simple questions concerning specific individuals, polynomial time algorithms are known. However, more useful questions, like "Could anyone who is not an employee ever get access?" are in general intractable. This paper concerns our efforts to build practical tools that answer such questions in many cases nevertheless by using a lightweight approach that leverages a mature model checking tool called SMV. Model checking is an automated technique that checks if desired properties hold in the model. Our experience, reported here, suggests that in our problem domain, such a tool may often be able to identify delegations that are unsafe with respect to security questions like the one mentioned above. We explain our translation from a RT policy and containment query to an SMV model and specification as well as demonstrate the feasibility of our approach with a case study.
机译:信任管理是访问控制的一种形式,它使用委派来实现超越单个组织或联盟的可伸缩性。但是,委派可能很难控制。委派某些权限的资源所有者自然要关心的是,不仅当今谁有权访问,而且在其他人对全局策略状态进行更改后,谁又将拥有访问权。他们需要工具来帮助回答这些问题。已经在称为RT的信任管理语言的情况下研究了此问题,其中对于涉及特定个人的简单问题,多项式时间算法是已知的。但是,还有一些更有用的问题,例如“不是雇员的人是否可以访问?”通常是棘手的。本文关注我们为构建实用工具而付出的努力,尽管如此,该工具还是使用轻量级方法来利用许多成熟的模型检查工具SMV来回答许多此类问题。模型检查是一种自动技术,用于检查模型中是否包含所需的属性。我们在这里报告的经验表明,在我们的问题域中,这样的工具通常可以识别出与上述安全问题有关的不安全委托。我们解释了从RT策略和遏制查询到SMV模型和规范的转换,并通过案例研究证明了我们方法的可行性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号