【24h】

An Approach to Access Control under Uncertainty

机译:不确定性下的访问控制方法

获取原文

摘要

In dynamic and uncertain environments such as healthcare, where the needs of security and information availability are difficult to balance, an access control approach based on a static policy will be suboptimal regardless of how comprehensive it is. The uncertainty stems from the unpredictability of users' operational needs as well as their private incentives to misuse permissions. In Role Based Access Control (RBAC), a user's legitimate access request may be denied because its need has not been anticipated by the security administrator. Alternatively, even when the policy is correctly specified an authorised user may accidentally or intentionally misuse the granted permission. This paper introduces a novel approach to access control under uncertainty and presents it in the context of RBAC. By taking insights from the field of economics, in particular the insurance literature, we propose a formal model where the value of resources are explicitly defined and an RBAC policy (entailing those predictable access needs) is only used as a reference point to determine the price each user has to pay for access, as opposed to representing hard and fast rules that are always rigidly applied.
机译:在动态和不确定的环境(例如医疗保健)中,难以平衡安全性和信息可用性的需求,基于静态策略的访问控制方法将是次优的,而不管其是否全面。这种不确定性源于用户操作需求的不可预测性以及他们滥用权限的私人动机。在基于角色的访问控制(RBAC)中,用户的合法访问请求可能会被拒绝,因为安全管理员尚未预料到其需求。或者,即使正确地指定了策略,授权用户也可能会意外或故意滥用授予的权限。本文介绍了一种在不确定情况下进行访问控制的新颖方法,并在RBAC的背景下进行了介绍。通过从经济学领域尤其是保险文献中获得见解,我们提出了一个正式模型,其中明确定义了资源的价值,并且RBAC策略(需要那些可预测的访问需求)仅用作确定价格的参考点每个用户都必须为访问付费,而不是代表始终严格应用的严格规则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号