首页> 外文会议>ACM symposium on access control models and technologies >The Authorization Leap from Rights to Attributes: Maturation or Chaos?
【24h】

The Authorization Leap from Rights to Attributes: Maturation or Chaos?

机译:从权利到属性的授权跨越:成熟还是混乱?

获取原文

摘要

The ongoing authorization leap from rights to attributes offers numerous compelling benefits. Decisions about user, subject, object and context attributes can be made relatively independently and with suitable decentralization appropriate for each attribute. Policies can be formulated by security architects to translate from attributes to rights. Dynamic elements can be built into these policies so the outcomes of access control decisions automatically adapt to changing local and global circumstances. On the benefits side this leap is a maturation of authorization matching the needs of emerging cyber technologies and systems. On the risks side devolving attribute management may lead to attributes of questionable provenance and value, with attendant possibility of new channels for social engineering and malware attacks. We argue that the potential benefits will lead to pervasive deployment of attribute-based access control (ABAC!), and more generally attribute-based security. The cyber security research community has a responsibility to develop models, theories and systems which enable safe and chaos-free deployment of ABAC. This is the current grand challenge for access control researchers.
机译:从权利到属性的持续授权飞跃提供了许多引人注目的好处。可以相对独立地做出关于用户,主题,对象和上下文属性的决策,并针对每个属性进行适当的分散。安全架构师可以制定策略以将属性从权利转换为权利。这些策略中可以内置动态元素,因此访问控制决策的结果会自动适应不断变化的本地和全局情况。在利益方面,这一飞跃是授权的成熟,可满足新兴网络技术和系统的需求。在风险方面,属性管理的下放可能导致属性的出处和价值受到质疑,并伴随着新的社交工程和恶意软件攻击渠道。我们认为,潜在的好处将导致基于属性的访问控制(ABAC!)以及更普遍的基于属性的安全性的广泛部署。网络安全研究界有责任开发模型,理论和系统,以实现ABAC的安全和无混乱部署。这是访问控制研究人员当前面临的巨大挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号