首页> 外文会议>International symposium on foundations and practice of security >HGABAC: Towards a Formal Model of Hierarchical Attribute-Based Access Control
【24h】

HGABAC: Towards a Formal Model of Hierarchical Attribute-Based Access Control

机译:HGABAC:建立基于分层属性的访问控制的正式模型

获取原文

摘要

Attribute-based access control (ABAC) is a promising alternative to traditional models of access control (i.e. discretionary access control (DAC), mandatory access control (MAC) and role-based access control (RBAC)) that is drawing attention in both recent academic literature and industry application. However, formaJization of a foundar tional model of ABAC and large scale adoption are still lacking. This paper seeks to aid in the transition by providing a formal model of hierarchical ABAC, called Hierarchical Group and Attribute-Based Access Control (or HGABAC), which includes attribute inheritance through user and object groups as well as environment, connection and administrative attributes. A formal specification and an attribute-based policy language are provided. Finally, several example configurations (which demonstrate the versatility of the model) axe presented and evaluated.
机译:基于属性的访问控制(ABAC)是传统访问控制模型(例如,自由访问控制(DAC),强制性访问控制(MAC)和基于角色的访问控制(RBAC))的一种有前途的替代方法,最近这两种方法都引起了人们的关注。学术文献和行业应用。但是,仍然缺乏ABAC的基本模型的形式化和大规模采用。本文试图通过提供一种称为ABAC的分层ABAC正式模型来帮助过渡,该模型称为分层组和基于属性的访问控制(HGABAC),其中包括通过用户和对象组以及环境,连接和管理属性进行的属性继承。提供了正式规范和基于属性的策略语言。最后,介绍并评估了几个示例配置(展示了模型的多功能性)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号