首页> 外文会议>IEEE Symposium on Security and Privacy >A logical language for expressing authorizations
【24h】

A logical language for expressing authorizations

机译:一种表达授权的逻辑语言

获取原文

摘要

A major drawback of existing access control systems is that they have all been developed with a specific access control policy in mind. This means that all protection requirements (i.e. accesses to be allowed or denied) must be specified in terms of the policy enforced by the system. While this may be trivial for some requirements, specification of other requirements may become quite complex or even impossible. The reason for this is that a single policy simply cannot capture the different protection requirements that users may need to enforce on different data. In this paper, we take a first step towards a model that is able to support different access control policies. We propose a logical language for the specification of authorizations on which such a model can be based. The Authorization Specification Language (ASL) allows users to specify, together with the authorizations, the policy according to which access control decisions are to be made. Policies are expressed by means of rules which enforce the derivation of authorizations, conflict resolution, access control and integrity constraint checking. We illustrate the power of our language by showing how different constraints that are sometimes required, but very seldom supported by existing access control systems, can be represented in our language.
机译:现有访问控制系统的主要缺点是它们都以特定的访问控制策略开发。这意味着必须在系统强制执行的策略方面指定所有保护要求(即允许或拒绝)。虽然某些要求可能是微不足道的,但其他要求的规格可能会变得非常复杂甚至不可能。原因是单一策略根本无法捕获用户可能需要对不同数据执行的不同保护要求。在本文中,我们迈出了一个能够支持不同访问控制策略的模型的第一步。我们提出了一种逻辑语言,用于规范此类模型可以基于的授权。授权规范语言(ASL)允许用户与授权一起指定,该策略根据哪个访问控制决策。通过强制执行授权,冲突解决,访问控制和完整性约束检查的规则表示策略。我们通过表示有时需要的不同约束,但是,我们的语言可以表示,通过显示有时需要的不同约束,而是很少支持我们的语言。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号