首页> 外文会议>2011 17th IEEE International Conference on Parallel and Distributed Systems >The Low-Cost Secure Sessions of Access Control Model for Distributed Applications by Public Personal Smart Cards
【24h】

The Low-Cost Secure Sessions of Access Control Model for Distributed Applications by Public Personal Smart Cards

机译:公共个人智能卡的分布式应用程序的低成本安全访问控制会话

获取原文

摘要

the secure requirement of modern information systems is increasing significantly nowadays, especially in cloud computing with distributed applications. Among secure mechanisms of an organization, the access control (AC) is a foundation for modern information systems. In order to reach an effective and flexible approach of access control, the Role-based Access Control (RBAC) models are widely deployed in organizations. Comparing with traditional discretionary access control (DAC) and mandatory access control (MAC), the user-role-subject mapping of a RBAC model provides effective permissions assignments for access control of an organization. However, the RBAC sessions could be stretched over multiple distributed servers in cloud computing. The traversed sessions between servers could be modified, monitored and attacked by modern hacker techniques, and become secure leaks in RBAC models. In order to ensure secure sessions in cloud computing, various encryption approaches are used. Among these encryption approaches, the use of digital certificates by asymmetric encryption methods could be an appropriate solution to ensure the security of RBAC sessions. However, the cost of public/private keys management and issuing an appropriate certificate tokens for each member in organizations could be very expensive. The high cost might block the deployment of secure RBAC sessions, and then reduce the secure level of organizations. In order to improve this issue, a low-cost approach of secure sessions for RBAC models is proposed in this paper. The personal smart cards can be used as a certificate tokens in RBAC models to reach effective user authentications. Moreover, each session of RBAC models, including user-role-subject assignments and content-based accesses, can be protected by digital certificates which is generated by user own smart cards. Thus the security of RBAC sessions can be improved significantly. It is worth noting that personal smart cards are issued by public depar--tments, thus the expense of tokens issuing and key management could be minimized. Therefore, the session security of a RBAC model could be ensured with user own smart cards without additional cost.
机译:如今,现代信息系统的安全要求正在显着提高,尤其是在具有分布式应用程序的云计算中。在组织的安全机制中,访问控制(AC)是现代信息系统的基础。为了获得有效和灵活的访问控制方法,基于角色的访问控制(RBAC)模型已在组织中广泛部署。与传统的自由访问控制(DAC)和强制访问控制(MAC)相比,RBAC模型的用户角色主题映射为组织的访问控制提供了有效的权限分配。但是,RBAC会话可以扩展到云计算中的多个分布式服务器上。服务器之间的遍历会话可以通过现代黑客技术进行修改,监视和攻击,并成为RBAC模型中的安全漏洞。为了确保云计算中的安全会话,使用了各种加密方法。在这些加密方法中,通过非对称加密方法使用数字证书可能是确保RBAC会话安全的合适解决方案。但是,公钥/私钥管理以及为组织中的每个成员发行适当的证书令牌的成本可能非常昂贵。高昂的成本可能会阻止安全RBAC会话的部署,从而降低组织的安全级别。为了改善这个问题,本文提出了一种针对RBAC模型的安全会话的低成本方法。可以将个人智能卡用作RBAC模型中的证书令牌,以达到有效的用户身份验证。此外,RBAC模型的每个会话(包括用户角色主题分配和基于内容的访问)都可以通过由用户自己的智能卡生成的数字证书进行保护。因此,可以显着提高RBAC会话的安全性。值得注意的是,个人智能卡是由公共部门发行的, -- 因此,可以最大程度地减少令牌发行和密钥管理的费用。因此,可以使用用户自己的智能卡来确保RBAC模型的会话安全性,而无需支付额外费用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号