首页> 外文会议>ACM symposium on access control models and technologies >A Framework Integrating Attribute-based Policies into Role-Based Access Control
【24h】

A Framework Integrating Attribute-based Policies into Role-Based Access Control

机译:将基于属性的策略集成到基于角色的访问控制的框架

获取原文

摘要

Integrated role-based access control (RBAC) and attribute-based access control (ABAC) is emerging as a promising paradigm. This paper proposes a framework that uses attribute-based policies to create a more traditional RBAC model. RBAC has been widely used, but ha.s weaknesses: it is labor-intensive and time-consuming to build a model instance, and a pure RBAC system lacks flexibility to efficiently adapt to changing users, objects, and security policies. Particularly, it is impractical to manually make (and maintain) user to role assignments and role to permission assignments in industrial context characterized by a large number of users and/or security objects. ABAC has features complimentary to RBAC, and merging RBAC and ABAC has become an important research topic. This paper proposes a new approach to integrating ABAC' with RBAC. by modeling RBAC in two levels. The aboveground level is a standard RBAC model extended with "environment". This level retains the simplicity of RBAC, .supporting RBAC model verification/review. The "underground" level is used to represent security knowledge in terms of attribute-based policies, which automatically create the simple RBAC model in the aboveground level. These attribute-based policies bring to RBAC the advantages of ABAC: they are easy to build and easy to adapt to changes. Using this framework, we tackle the problem of permission assignment for large scale applications. This model is motivated by the characteristics and requirements of industrial control systems, and reflects in part certain approaches and practices common in the industry.
机译:基于集成的基于角色的访问控制(RBAC)和基于属性的访问控制(ABAC)被涌现为有前途的范例。本文提出了一种使用基于属性的策略来创建更传统的RBAC模型的框架。 RBAC已被广泛使用,但缺点:构建模型实例是劳动密集型和耗时的耗时,纯粹的RBAC系统缺乏有效适应更改用户,对象和安全策略的灵活性。特别地,手动制作(并维护)用户在由大量用户和/或安全对象中的特征在一起的工业上下文中的权限分配中解释和角色是不切实际的。 ABAC酒店提供免费RBAC,并合并RBAC和ABAC已成为一个重要的研究主题。本文提出了一种将ABAC与RBAC集成的新方法。通过在两个层面建模RBAC。地下水平是一个标准的RBAC模型,其中包含“环境”。此级别保留了RBAC的简单性,。支持RBAC模型验证/审查。 “地下”级别用于代表基于属性的策略方面的安全知识,它在地下级别自动创建简单的RBAC模型。这些基于属性的策略带来了RBAC ABAC的优势:它们很容易构建,易于适应变化。使用此框架,我们解决大规模应用程序权限分配问题。该模型具有工业控制系统的特点和要求,并反映了行业中常见的某些方法和实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号