首页> 外文会议> >Ensuring Authorization Privileges for Cascading User Obligations
【24h】

Ensuring Authorization Privileges for Cascading User Obligations

机译:确保级联用户义务的授权特权

获取原文

摘要

User obligations are actions that the human users are required to perform in some future time. These are common in many practical access control and privacy and can depend on and affect the authorization state. Consequently, a user can incur an obligation that she is not authorized to perform which may hamper the usability of a system. To mitigate this problem, previous work introduced a property of tlie authorization state, accountability, which requires that all the obligatory actions to be authorized when they are attempted. Although, existing work provides a specific and tractable decision procedure for a variation of the accountability property, it makes a simplified assumption that no cascading obligations may happen, i.e., obligatory actions cannot further incur obligations. This is a strong assumption which reduces the expressive power of past models, and thus cannot support many obligation scenarios in practical security and privacy policies. In this work, we precisely specify the strong accountability property in the presence of cascading obligations and prove that deciding it is NP-hard. We provide for several special yet practical cases of cascading obligations (i.e., repetitive, finite cascading, etc.) a tractable decision procedure for accountability. Our experimental results illustrate that supporting such special cases is feasible in practice.
机译:用户义务是人类用户将来需要执行的操作。这些在许多实际的访问控制和隐私中很常见,并且可能取决于并影响授权状态。因此,用户可能会承担她无权执行的义务,这可能会妨碍系统的可用性。为了缓解此问题,以前的工作引入了授权状态即问责制的属性,该属性要求所有强制性措施在尝试时都必须得到授权。尽管现有工作为追究责任属性的变化提供了一种具体且易于处理的决策程序,但它简化了一个假设,即不会发生任何级联义务,即,强制性行为不能进一步产生义务。这是一个强有力的假设,会降低过去模型的表达能力,因此无法支持实际安全性和隐私策略中的许多义务方案。在这项工作中,我们精确地指定了存在级联义务时强大的问责制属性,并证明确定它是NP难的。我们提供了级联义务的几种特殊但实用的案例(即重复性,有限级联等),这是一种易于处理的问责决策程序。我们的实验结果表明,在实践中支持此类特殊情况是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号