【24h】

Fine-Grained Disclosure of Access Policies

机译:细粒度披露访问政策

获取原文

摘要

In open scenarios, where servers may receive requests to access their services from possibly unknown clients, access control is typically based on the evaluation of (certified or uncertified) properties, that clients can present. Since assuming the client to know a-priori the properties she should present to acquire access is clearly limiting, servers should be able to respond to client requests with information on the access control policies regulating access to the requested services. In this paper, we present a simple, yet flexible and expressive, approach for allowing servers to specify disclosure policies, regulating if and how access control policies on services can be communicated to clients. Our approach allows fine-grain specifications, thus capturing different ways in which policies, and portions thereof, can be communicated. We also define properties that can characterize the client view of the access control policy.
机译:在开放方案中,服务器可以接收从可能未知的客户端访问其服务的请求,访问控制通常基于(认证或未认证)属性的评估,该客户端可以存在。由于假设客户知道a-priortio,因此她应该出示的属性来获取访问是明确限制的,因此服务器应该能够响应客户端请求,以便在调节对所请求的服务的访问权限的访问控制策略的信息响应客户端请求。在本文中,我们提出了一种简单,灵活且富有敏感的方法,用于允许服务器指定披露策略,调节如果可以向客户端传送服务的访问控制策略。我们的方法允许细粒度规格,从而捕获其在哪些政策和部分的不同方式可以传送。我们还定义了可以为访问控制策略的客户端视图表征的属性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号