首页> 外文会议>ACM symposium on access control models and technologies >A Framework Integrating Attribute-based Policies into Role-Based Access Control
【24h】

A Framework Integrating Attribute-based Policies into Role-Based Access Control

机译:将基于属性的策略集成到基于角色的访问控制中的框架

获取原文

摘要

Integrated role-based access control (RBAC) and attribute-based access control (ABAC) is emerging as a promising paradigm. This paper proposes a framework that uses attribute-based policies to create a more traditional RBAC model. RBAC has been widely used, but ha.s weaknesses: it is labor-intensive and time-consuming to build a model instance, and a pure RBAC system lacks flexibility to efficiently adapt to changing users, objects, and security policies. Particularly, it is impractical to manually make (and maintain) user to role assignments and role to permission assignments in industrial context characterized by a large number of users and/or security objects. ABAC has features complimentary to RBAC, and merging RBAC and ABAC has become an important research topic. This paper proposes a new approach to integrating ABAC' with RBAC. by modeling RBAC in two levels. The aboveground level is a standard RBAC model extended with "environment". This level retains the simplicity of RBAC, .supporting RBAC model verification/review. The "underground" level is used to represent security knowledge in terms of attribute-based policies, which automatically create the simple RBAC model in the aboveground level. These attribute-based policies bring to RBAC the advantages of ABAC: they are easy to build and easy to adapt to changes. Using this framework, we tackle the problem of permission assignment for large scale applications. This model is motivated by the characteristics and requirements of industrial control systems, and reflects in part certain approaches and practices common in the industry.
机译:基于角色的访问控制(RBAC)和基于属性的访问控制(ABAC)的集成正在成为一种有希望的范例。本文提出了一个框架,该框架使用基于属性的策略来创建更传统的RBAC模型。 RBAC已被广泛使用,但是有一个缺点:构建模型实例非常耗时且费力,而且纯RBAC系统缺乏有效地适应变化的用户,对象和安全策略的灵活性。特别是,在以大量用户和/或安全对象为特征的工业环境中,手动进行(和维护)用户角色分配和权限许可分配是不切实际的。 ABAC具有RBAC以外的功能,并且将RBAC与ABAC合并已成为重要的研究课题。本文提出了一种将ABAC'与RBAC集成的新方法。通过在两个级别上对RBAC进行建模。地上级别是带有“环境”扩展的标准RBAC模型。该级别保留了RBAC的简单性,支持RBAC模型验证/审查。 “地下”级别用于表示基于属性的策略的安全性知识,该属性会在地面级别自动创建简单的RBAC模型。这些基于属性的策略为RBAC带来了ABAC的优势:它们易于构建且易于适应变化。使用此框架,我们解决了大型应用程序的权限分配问题。该模型受工业控制系统的特征和要求的驱动,并部分反映了行业中常见的某些方法和实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号