【24h】

Enforcing Separation of Duty in Ad Hoc Collaboration

机译:加强临时协作中的职责分离

获取原文

摘要

By collaboration, domains share resources effectively. To maintain security properties of individual domains during collaboration is a key issue. When domains employing heterogeneous RBAC policies collaborate by crossdomain role-role mappings, their local SMER constraints may be violated. However, the secure interoperation studied so far does not deal with this threat. We presents the requirement for constraint secure interoperation, prohibiting implicit authorizations that break constraints of other member domain. We propose a framework for crossdomain constraint enforcement in dynamic mediator-free ad hoc collaboration. By introducing crossdomain migration of MD-SMERs, the framework ensures the global security in terms of SMERs from individual domains. Specifically, we introduce a bitmap-based history-recording mechanism for collaborating domains to analyze the interplay among innerdomain role hierarchies, crossdomain role-role mappings, and SMER constraints. Algorithms of a fully distributed implementation for the framework and its security proofs are given.
机译:通过协作,域可以有效地共享资源。在协作期间维护各个域的安全性是一个关键问题。当采用异构RBAC策略的域通过跨域角色角色映射进行协作时,可能会违反其本地SMER约束。但是,到目前为止研究的安全互操作不能解决这种威胁。我们提出了约束安全互操作的要求,禁止隐式授权破坏其他成员域的约束。我们提出了一种在无中介的动态临时协作中执行跨域约束的框架。通过引入MD-SMER的跨域迁移,该框架确保了来自各个域的SMER的全局安全性。具体来说,我们引入了一种基于位图的历史记录机制来协作域,以分析内部域角色层次结构,跨域角色角色映射和SMER约束之间的相互作用。给出了该框架的完全分布式实现的算法及其安全性证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号