首页> 外文会议>IEEE Computer Security Foundations Symposium >Do As I SaY! Programmatic Access Control with Explicit Identities
【24h】

Do As I SaY! Programmatic Access Control with Explicit Identities

机译:照我说的做!具有明确标识的程序化访问控制

获取原文

摘要

We address the programmatic realization of the access control model of security in distributed systems. Our aim is to bridge the gap between abstract/declarative policies and their concrete/operational implementations. We present a programming formalism (which extends the asynchronous pi-calculus with explicit principals) and a specification logic (which extends Datalog with primitives from authorization logic). We provide two kinds of static analysis methods to tie implementation to specification. Type checking determines that a program is a sound implementation of policy; i.e., that all granted accesses are safe in the face of arbitrary opponents. Model checking determines a degree of completeness; i.e., that accesses permitted by the policy are actually granted in the implementation.
机译:我们解决了分布式系统中安全性访问控制模型的程序化实现。我们的宗旨是弥合抽象/陈述政策与其具体/运营实施之间的差距。我们介绍了一个编程形式主义(扩展了具有明确原理的异步PI-Calculus)和规范逻辑(它将Datalog与来自授权逻辑的基元扩展)。我们提供两种静态分析方法来连接到规范。类型检查确定程序是策略的声音实现;即,所有授予的访问都在面对任意对手时是安全的。模型检查确定完整程度;即,实际授予该策略允许的访问的访问。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号