首页> 外文会议>ACM symposium on access control models and technologies >Access Control Policy Translation and Verification within Heterogeneous Data Federations
【24h】

Access Control Policy Translation and Verification within Heterogeneous Data Federations

机译:访问控制策略转换与异构数据联合中的验证

获取原文

摘要

Data federations provide seamless access to multiple heterogeneous and autonomous data sources pertaining to a large organization. As each source database defines its own access control policies for a set of local identities, enforcing such policies across the federation becomes a challenge. In this paper, we first consider the problem of translating existing access control policies defined over source databases in a manner that allows the original semantics to be observed, while becoming applicable across the entire data federation. We show that such a translation is always possible, and provide an algorithm for automating the translation. We then show that verifying that a translated policy obeys the semantics of the original access control policy defined over a source database is intractable, even under restrictive scenarios. Finally, we describe a practical algorithmic framework for translating relational access control policies into their XML equivalent, expressed in the extensible Access Control Markup Language.
机译:数据联合提供对与大型组织有关的多个异构和自主数据源的无缝访问。由于每个源数据库定义了一组本地身份的自己的访问控制策略,因此强制执行联合会的此类策略成为挑战。在本文中,我们首先考虑以允许观察到的原始语义的方式翻译在源数据库上定义的现有访问控制策略的问题,同时在整个数据联合中适用。我们表明,始终可以进行这种转换,并提供用于自动化翻译的算法。然后,我们谨验证翻译的政策obeys在源数据库中定义的原始访问控制策略的语义即使在限制方案下也是棘手的。最后,我们描述了一种实用的算法框架,用于将关系访问控制策略转换为XML等效物中的XML等效项,以可扩展访问控制标记语言表示。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号