首页> 外文会议>Annual Computer Security Applications Conference >A distributed implementation of the extended schematic protection model
【24h】

A distributed implementation of the extended schematic protection model

机译:扩展原理化保护模型的分布式实现

获取原文

摘要

Protection models provide a formalism for specifying control over access to information and other resources in a multi-user computer system. One such model, the extended schematic protection model (ESPM) has expressive power equivalent to the monotonic access matrix model of Harrison, Ruzzo, and Ullman (1976). Yet ESPM retains tractable safety analysis for many cases of practical interest. Thus ESPM is a very general model, and it is of interest whether ESPM can be implemented in a reasonable manner. The authors outline a distributed implementation for ESPM. The implementation is capability-based, with an architecture where servers act as mediators to all subject and object access. Capabilities are made nontransferable by burying the identity of subjects in them, and unforgeable by using a public key encryption algorithm. Timestamps and public keys are used as mechanisms for revocation.
机译:保护模型提供了一种形式主义,用于指定对多用户计算机系统中的信息和其他资源的控制来指定控制。一个这样的模型,扩展原理化保护模型(ESPM)具有相当于Harrison,Ruzzo和Ullman(1976)的单调访问矩阵模型的表现力。然而,ESPM为许多实际兴趣的情况保留了易易行的安全分析。因此,ESPM是一个非常一般的模型,它是兴趣的,是否可以以合理的方式实现ESPM。作者概述了ESPM的分布式实施。实现是基于功能的,具有服务器充当所有主题和对象访问的校准。通过使用公钥加密算法掩盖它们中的主题的身份和不可推动的功能,不能使能力不可转让。时间戳和公钥用作撤销机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号