首页> 外文会议>IEEE Symposium on Security and Privacy >Access control in an open distributed environment
【24h】

Access control in an open distributed environment

机译:打开分布式环境中的访问控制

获取原文

摘要

We describe an architecture for secure, independent, interworking services (Oasis). Each service is made responsible for the classification of its clients into named roles, using a formal logic to specify precise conditions for entering each role. A client becomes authenticated by presenting credentials to a service that enable the service to prove that the client conforms to its policy for entry to a particular role. During authentication a data structure is created that embodies the proof. An authenticated client is issued a role membership certificate (RMC) for its subsequent use with that service. An RMC is an encryption-protected capability which includes the role name, the identity of the principal to which it was issued and a reference to the issuing service. A proof rule of one service may refer to an authenticated user of another; that is, an RMC issued by one service may be required as a credential during authentication by another. A dynamic proof tree may thus be built which exhibits amongst other things the trust relationships between the services which the client has entered. The paper shows how a service may define a set of proof rules (Horn clauses) that specify who may use it and in what way. Delegation of rights may be expressed naturally within these rules. It goes on to present the design details of the system. The system is inherently decentralised and has a tuneable reaction to network or server failure which allows services to make appropriate decisions when authorization or revocation information is unavailable. A prototype system has been implemented and tested.
机译:我们描述了安全,独立,互通服务(OASIS)的架构。每个服务都是负责使用形式逻辑对其客户端进行分类,以指定输入每个角色的精确条件。通过将凭据呈现给服务来证明客户端符合其用于输入特定角色的策略来进行身份验证,客户端通过呈现凭据进行身份验证。在身份验证期间,创建数据结构,其体现了证明。经过身份验证的客户端被发出角色成员身份证书(RMC),以便随后与该服务一起使用。 RMC是一种受加密保护的能力,包括角色名称,发出的本金的身份以及对发行服务的引用。一个服务的证明规则可以指代认证的另一个用户;也就是说,可以在通过另一个服务期间作为凭证作为凭证所需的RMC。因此,可以构建动态证明树,其在客户端输入的服务之间的信任关系中展示。本文显示了服务如何定义一组证明规则(喇叭子句),该规则指定谁可以使用它和以何种方式。权利授权可以在这些规则中自然地表达。它继续呈现系统的设计细节。该系统本质地分散,对网络或服务器故障具有可调调度,其允许服务在授权或撤销信息不可用时进行适当的决策。已经实现和测试了原型系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号