【24h】

A usage control policy specification with Petri nets

机译:用Petri网进行使用控制策略规范

获取原文

摘要

In this paper we propose a novel usage control policy specification based on Coloured Petri Nets formalism. Recently, usage control has been proposed in order to overcome the shortcomings of transitional access control that fails to meet new security requirements of today's highly dynamic and distributed systems. These new environments require for example (i) a continuity of control, (ii) fulfillment checks of obligatory tasks, during or after the usage end, (iii) an integration between functional behavior and security policy, and (iv) the management and control of concurrent and parallel usages by different subjects. Taking all these requirements into consideration, our usage control policy includes three main rule types: behavioral, security and concurrency rules. Security rules, can be further classified either into instant-, -ongoing, and post rules or into authorization and obligation rules. Instant rules must be checked before the execution of an action is granted, ongoing rules are checked during the execution of an action, and finally post rules are checked after the execution is finished. Therefore, post rules are only of type obligation. Coloured Petri nets are used because of their powerful modeling capabilities of distributed and concurrent systems and their efficiency for specification of systems by embodying the support of ML functional programming language.
机译:在本文中,我们提出了一种基于彩色Petri网形式主义的新型使用控制策略规范。最近,已经提出了使用控制,以克服过渡进入控制的缺点,该控制无法满足当今高度动态和分布式系统的新安全要求。这些新环境要求(i)控制的连续性,(ii)使用结束期间或之后的义务任务,(iii)功能行为和安全策略之间的集成,(iv)管理和控制不同主题的并发和并行使用。考虑所有这些要求,我们的使用控制策略包括三种主要规则类型:行为,安全性和并发规则。安全规则,可以进一步分为即时, - oonging和邮政规则或授权和义务规则。必须在授予操作之前检查即时规则,在执行操作期间检查正在进行的规则,并且在执行完成后将检查最终的后规则。因此,邮政规则仅是义务。由于它们通过体现ML功能规划语言的支持,因此使用了彩色培养网,因为它们的分布式和并发系统的强大建模能力及其对系统规范的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号