首页> 外文会议>ACM workshop on Secure web services >An extended RBAC profile of XACML
【24h】

An extended RBAC profile of XACML

机译:XACML的扩展RBAC配置文件

获取原文

摘要

Nowadays many organizations use security policies to control access to sensitive resources. Moreover, exchanging or sharing services and resources is essential for these organizations to achieve their business objectives. Since the eXtensible Access Control Markup Language (XACML) was standardized by the OASIS community, it has been widely deployed, making it easier to interoperate with other applications using the same standard language. The OASIS has defined an RBAC profile of XACML that illustrates how organizations that would like to use the RBAC model can express their access control policy within this standard language. This work analyzes the RBAC profile of XACML, showing its limitations to respond to all the requirements for access control. We then suggest adding some functionalities within an extended RBAC profile of XACML. This new profile is expected to respond to more advanced access control requirements such as user-user delegation, access elements abstractions and contextual applicability of the policies.
机译:如今,许多组织使用安全策略来控制对敏感资源的访问。此外,交换或共享服务和资源对于这些组织实现其业务目标至关重要。自OASIS社区对可扩展访问控制标记语言(XACML)进行标准化以来,它已得到广泛部署,从而使使用相同标准语言与其他应用程序进行互操作变得更加容易。 OASIS定义了XACML的RBAC概要文件,该概要文件说明了希望使用RBAC模型的组织如何在此标准语言中表达其访问控制策略。这项工作分析了XACML的RBAC配置文件,显示了其对响应所有访问控制要求的限制。然后,我们建议在XACML的扩展RBAC配置文件中添加一些功能。预期此新配置文件将响应更高级的访问控制要求,例如用户-用户委派,访问元素抽象和策略的上下文适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号