首页> 外文会议>ACM symposium on access control models and technologies >Ensuring Authorization Privileges for Cascading User Obligations
【24h】

Ensuring Authorization Privileges for Cascading User Obligations

机译:确保级联用户义务的授权权限

获取原文

摘要

User obligations are actions that the human users are required to perform in some future time. These are common in many practical access control and privacy and can depend on and affect the authorization state. Consequently, a user can incur an obligation that she is not authorized to perform which may hamper the usability of a system. To mitigate this problem, previous work introduced a property of tlie authorization state, accountability, which requires that all the obligatory actions to be authorized when they are attempted. Although, existing work provides a specific and tractable decision procedure for a variation of the accountability property, it makes a simplified assumption that no cascading obligations may happen, i.e., obligatory actions cannot further incur obligations. This is a strong assumption which reduces the expressive power of past models, and thus cannot support many obligation scenarios in practical security and privacy policies. In this work, we precisely specify the strong accountability property in the presence of cascading obligations and prove that deciding it is NP-hard. We provide for several special yet practical cases of cascading obligations (i.e., repetitive, finite cascading, etc.) a tractable decision procedure for accountability. Our experimental results illustrate that supporting such special cases is feasible in practice.
机译:用户义务是人类用户需要在未来时间执行的措施。这些在许多实际访问控制和隐私中是常见的,并且可以取决于并影响授权状态。因此,用户可能会产生一个义务她未被授权执行的义务可能妨碍系统的可用性。为了缓解此问题,之前的工作介绍了TLIE授权国,问责制的属性,要求在尝试时授权的所有强制性行动。虽然现有工作为责任财产的变更提供了一个具体和贸易的决定程序,但它使得简化假设可以发生级联义务,即,强制性行动不能进一步招致义务。这是一个强大的假设,这减少了过去模型的表现力,因此不能支持实际安全和隐私政策中的许多义务场景。在这项工作中,我们恰恰指定的级联义务存在的强有力的问责性和证明,决定它是NP难。我们提供了几种特殊但是实际的级联义务案例(即重复,有限级联等)一个责任决定程序。我们的实验结果表明,支持这种特殊情况在实践中是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号