【24h】

Towards provenance-based access control with feasible overhead

机译:以可行的开销实现基于源的访问控制

获取原文

摘要

Provenance is a directed graph that explains how a data item became what it is. It is recently proposed to use provenance to enable the so-called provenance-based access control (PBAC) in provenance-aware systems. Evaluating a PBAC policy usually involves one or more queries against provenance store. However, directly reusing existing provenance query engines in a PBAC enforcement framework may introduce unacceptable performance overhead because provenance store might grow to immense size. This paper argues that feasible performance overhead for evaluating a PBAC policy must be under a nearly fixed threshold that is tolerable for users no matter how big the provenance store is. This paper designs several tactics, in particular a PBAC-specific tactic-adding shortcuts in a provenance graph, to partially satisfy this requirement. Finally, we analyze several open questions with respect to adopting these tactics.
机译:来源是一个有向图,用于说明数据项如何变成其原样。最近提出了使用出处来在出处感知系统中实现所谓的基于出处的访问控制(PBAC)。评估PBAC策略通常涉及针对来源存储的一个或多个查询。但是,在PBAC实施框架中直接重用现有的出处查询引擎可能会导致无法接受的性能开销,因为出处存储可能会增长到巨大的规模。本文认为,评估PBAC策略的可行性能开销必须在几乎固定的阈值以下,无论来源存储多大,用户都可以容忍该阈值。本文设计了几种策略,特别是在出处图中添加了PBAC特定的策略添加快捷方式,以部分满足此要求。最后,我们分析了有关采用这些策略的几个未解决的问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号