首页> 外文会议>IEEE Symposium on Security and Privacy >On the Formal Definition of Separation-of-Duty Policies and their Composition
【24h】

On the Formal Definition of Separation-of-Duty Policies and their Composition

机译:论廉价政策及其组成的正式定义

获取原文

摘要

In this paper we define formally a wide variety of separation-of-duty (SoD) properties, which include the best known to date, and establish their relationships within a formal model of role-based access control (RBAC). The formalism helps remove all ambiguities of informal definition, and offers a wide choice of implementation strategies. We also explore the composability of SoD properties and policies under a simple criterion. We conclude that practical implementation for SoD policies requires new methods and tools for security administration even within applications that already support RBAC, such as most database management systems.
机译:在本文中,我们正式定义了各种各样的职业性分离(SOD)属性,包括最熟悉的迄今为止,并在基于角色的访问控制(RBAC)的正式模型中建立它们的关系。形式主义有助于消除非正式定义的所有模糊性,并提供各种实施策略。我们还在简单标准下探索SOD性能和政策的可兼职性。我们得出结论,即使在已经支持RBAC的应用程序中,SOD策略的实际实施需要用于安全管理的新方法和工具,例如大多数数据库管理系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号