首页> 外文会议>ACM symposium on access control models and technologies >The Authorization Leap from Rights to Attributes: Maturation or Chaos?
【24h】

The Authorization Leap from Rights to Attributes: Maturation or Chaos?

机译:从权限到属性的授权跳跃:成熟或混乱?

获取原文

摘要

The ongoing authorization leap from rights to attributes offers numerous compelling benefits. Decisions about user, subject, object and context attributes can be made relatively independently and with suitable decentralization appropriate for each attribute. Policies can be formulated by security architects to translate from attributes to rights. Dynamic elements can be built into these policies so the outcomes of access control decisions automatically adapt to changing local and global circumstances. On the benefits side this leap is a maturation of authorization matching the needs of emerging cyber technologies and systems. On the risks side devolving attribute management may lead to attributes of questionable provenance and value, with attendant possibility of new channels for social engineering and malware attacks. We argue that the potential benefits will lead to pervasive deployment of attribute-based access control (ABAC!), and more generally attribute-based security. The cyber security research community has a responsibility to develop models, theories and systems which enable safe and chaos-free deployment of ABAC. This is the current grand challenge for access control researchers.
机译:来自属性权的正在进行的授权跨越提供众多引人注目的福利。关于用户,主题,对象和上下文属性的决策可以相对独立地进行,并且适合每个属性的合适的分权。可以通过安全架构师构起策略来从属性转换为权限。动态元素可以内置于这些策略中,因此访问控制决策的结果会自动适应改变本地和全局情况。在福利方面,这一飞跃是授权的成熟,符合新兴网络技术和系统的需求。在风险的侧面偏离属性管理可能导致可疑的出处和价值的属性,具有新渠道的社会工程和恶意软件攻击的能力。我们认为潜在的好处将导致基于属性的访问控制(ABAC!)的普遍部署,以及更广泛的基于属性的安全性。网络安全研究界有责任开发能够安全和无笨拙部署ABAC的模型,理论和系统。这是当前访问控制研究人员的大挑战。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号