【24h】

Modular authorization

机译:模块化授权

获取原文

摘要

There are three major drawbacks of a centralized security administration in distributed systems: It creates a bottleneck for request handling, it tends to enforce homogeneous security structures in heterogeneous user groups and organizations, and it is a weak point in terms of security attacks, reliability, and fault tolerance. In this paper we introduce a distributed authorization concept which is based on a modular authorization language for supporting cooperatingdistributed authorization teams. These teams are partially ordered into a hierarchy in that they inherit authorization rules from higher order teams but still exercise their autonomy by (dynamically) setting local rules that serve the special local needs in distributed organizations.Conflictsbetween between rules inherited from different higher ranking sources, orviolationsof higher order rules through local rules would be detected, on the logical level or through request evaluation,as contradictions or contradicting results, respectively. Conflict resolution mechanisms are presented, and examples are discussed extensively.

机译:

分布式系统中的集中式安全管理存在三个主要缺点:它创建了请求处理的瓶颈,倾向于在异构用户组和组织中实施同类的安全结构,并且在安全攻击方面是薄弱点。 ,可靠性和容错能力。在本文中,我们介绍了一种基于模块化授权语言的分布式授权概念,用于支持合作的分布式授权团队。这些团队被部分排序到一个层次结构中,因为它们继承了较高级别团队的授权规则,但仍通过(动态)设置服务于分布式组织中特殊的本地需求的本地规则来行使其自治权。冲突从逻辑上或通过请求评估,从不同的较高级别来源继承的规则或通过本地规则的违反分别被检测为矛盾或矛盾结果。提出了解决冲突的机制,并对实例进行了广泛的讨论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号