首页> 外文会议>Annual IFIP WG 11.3 conference on data and applications security and privacy >Fast Distributed Evaluation of Stateful Attribute-Based Access Control Policies
【24h】

Fast Distributed Evaluation of Stateful Attribute-Based Access Control Policies

机译:基于状态的基于属性的访问控制策略的快速分布式评估

获取原文

摘要

Separation of access control logic from other components of applications facilitates uniform enforcement of policies across applications in enterprise systems. This approach is popular in attribute-based access control (ABAC) systems and is embodied in the XACML standard. For this approach to be practical in an enterprise system, the access control decision engine must be scalable, able to quickly respond to access control requests from many concurrently running applications. This is especially challenging for stateful (also called history-based) access control policies, in which access control requests may trigger state updates: This paper presents an policy evaluation algorithm for stateful ABAC policies that achieves high throughput by distributed processing, using a specialized multi-version concurrency control scheme to deal with possibly conflicting concurrent updates. The algorithm is especially designed to achieve low latency, by minimizing the number of messages on the critical path of each access control decision.
机译:将访问控制逻辑与应用程序的其他组件分开,有助于在企业系统中跨应用程序统一实施策略。这种方法在基于属性的访问控制(ABAC)系统中很流行,并且在XACML标准中得到了体现。为了使这种方法在企业系统中可行,访问控制决策引擎必须具有可伸缩性,能够快速响应来自许多同时运行的应用程序的访问控制请求。这对于有状态(也称为基于历史记录)的访问控制策略尤其具有挑战性,其中访问控制请求可能会触发状态更新:本文提出了一种针对状态ABAC策略的策略评估算法,该算法通过使用专用版本并发控制方案来处理可能冲突的并发更新。通过最小化每个访问控制决策的关键路径上的消息数,该算法经过专门设计以实现低延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号