首页> 外文会议>Annual Computer Security Applications Conference >An authorization plan for commercial service systems
【24h】

An authorization plan for commercial service systems

机译:商业服务系统的授权计划

获取原文

摘要

Commercial service systems should allow customers to control their service configurations. The challenge is to make this feature feasible in such a way that the system is easy to administer while ensuring the security of both customer's service and the control system itself. Simple security mechanisms, such as access control lists used in general-purpose computer systems, are insufficient for administration control and authority delegation in commercial service systems. The author proposes a security policy called an 'authorization policy' suitable for administration and authorization controls. This security policy is enforced through a unified protection mechanism called an 'access control hierarchy'. The application of this access control hierarchy is demonstrated by examples.
机译:商业服务系统应允许客户控制其服务配置。挑战是使这一特征可行,使系统易于管理,同时确保客户服务和控制系统本身的安全性。简单的安全机制,例如通用计算机系统中使用的访问控制列表,在商业服务系统中的管理控制和权限代表中不足。作者提出了一个称为“授权策略”的安全策略,适用于管理和授权控制。通过称为“访问控制层次结构”的统一保护机制,强制执行此安全策略。示例演示了该访问控制层次结构的应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号