【24h】

Optimal Workflow-aware Authorizations

机译:最佳工作流程感知授权

获取原文

摘要

Balancing protection and empowerment- is a central problem when specifying authorizations. The principle of least privilege, the classical approach to balancing these two conflicting objectives, says that users shall only be authorized to execute the tasks necessary to complete their job. However, when there are multiple authorization policies satisfying least privilege, which one should be chosen? In this paper, we model the tasks that users must execute as workflows, and the risk and cost associated with authorization policies and their administration. We then formulate the balancing of empowerment and protection as an optimization problem: finding a cost-minimizing authorization policy that allows a successful workflow execution. We show that finding an optimal solution for a role-based cost function is NP-complete. We support our results with a series of examples, which we also use to measure the performance of our prototype implementation.
机译:平衡保护和赋权 - 在指定授权时是一个核心问题。最重要的原则,平衡这两个冲突目标的古典方法,说用户只能被授权执行完成工作所需的任务。但是,当有多种授权策略满足最少特权时,应该选择哪一个?在本文中,我们模拟了用户必须作为工作流程的任务以及与授权政策及其管理相关的风险和成本。然后,我们将赋权和保护的平衡为优化问题:找到一种成本最小化的授权策略,允许成功的工作流执行。我们显示为基于角色的成本函数找到最佳解决方案是NP-Complete。我们通过一系列示例支持我们的结果,我们还用于衡量我们的原型实施的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号