首页> 外文会议>Computer Security Applications Conference >A Policy Validation Framework for Enterprise Authorization Specification
【24h】

A Policy Validation Framework for Enterprise Authorization Specification

机译:企业授权规范的策略验证框架

获取原文
获取外文期刊封面目录资料

摘要

The validation of enterprise authorization specification for conformance to enterprise security policies requires an out-of-band framework in many situations since the enforcing access control mechanism does not provide this feature. In this paper we describe one such framework. The framework uses XML to encode the enterprise authorization specification, XML Schema to specify the underlying access control model (which in our case is the Role-based Access control Model (RBAC)) and Schematron language to encode the policy constraints. The conformance of the XML-encoded enterprise authorization specification to the structure of the RBAC model (specified through XML Schema) as well as the policy constaints (specified through Schematron) are verified through a Schematron Validator tool.
机译:企业授权规范符合企业安全策略的验证需要许多情况下的带外框架,因为强制访问控制机制不提供此功能。在本文中,我们描述了一个这样的框架。该框架使用XML来编码企业授权规范,XML架构指定基础访问控制模型(在我们的情况下是基于角色的访问控制模型(RBAC))和Schematron语言来编码策略约束。 XML编码的企业授权规范对RBAC模型的结构(通过XML模式指定)以及通过Schematron Validator工具验证策略构件(指定通过XML模式)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号