首页> 外文会议>2011 Sixth International Conference on Availability, Reliability and Security >Evaluating RBAC Supported Techniques and their Validation and Verification
【24h】

Evaluating RBAC Supported Techniques and their Validation and Verification

机译:评估RBAC支持的技术及其验证和验证

获取原文

摘要

This paper evaluates the security specification techniques that employ Role Based Access Control (RBAC) variants. RBAC offers a special kind of access control mechanism based on the use of roles to grant permissions. Its variants include role hierarchy and separation of duty (SoD) constraints. The overall management of a RBAC supported system is made through its administrative, review and supporting system functions. In this paper, a summary of semi-formal and formal techniques employing RBAC is provided along with their benefits and limitations. Here, semi-formal techniques refer to UML+OCL while formal ones are based on Alloy. This paper may guide through the process of selecting an appropriate technique to specify security rules. This is done by analyzing the degree of coverage of RBAC including some extensions like SoD and role hierarchy. We also investigate the use of validation and verification tools in these techniques. We find that formal techniques are more amenable to automated analysis as compared to semi-formal ones. Semi-formal techniques are rich in specifying RBAC variants but have prototypic tools. Session based dynamic aspects of RBAC have been partly covered in both techniques.
机译:本文评估了采用基于角色的访问控制(RBAC)变体的安全规范技术。 RBAC根据使用角色授予权限来提供一种特殊的访问控制机制。它的变体包括角色层次结构和职责分离(SoD)约束。 RBAC支持的系统的整体管理是通过其管理,审查和支持系统功能来进行的。在本文中,提供了使用RBAC的半正式和正式技术的摘要以及它们的优点和局限性。在这里,半正式技术是指UML + OCL,而正式技术是基于Alloy。本文可能会指导您选择合适的技术来指定安全规则的过程。这是通过分析RBAC的覆盖程度(包括SoD和角色层次结构的某些扩展)来完成的。我们还研究了在这些技术中使用验证和验证工具的情况。我们发现,与半正式技术相比,正式技术更适合自动化分析。半正式技术在指定RBAC变体方面很丰富,但具有原型工具。两种技术都部分涵盖了基于会话的RBAC动态方面。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号