首页> 外文会议>ACM symposium on Access control models and technologies >A meta model for authorisations in application security systems and their integration into RBAC administration
【24h】

A meta model for authorisations in application security systems and their integration into RBAC administration

机译:应用安全系统中授权的元模型及其在RBAC管理中的集成

获取原文

摘要

This paper presents a new concept for efficient access rights administration and access control. It focuses on the special requirements of application security and reflects experiences from the implementation of security for large industry application systems. Application security shows a considerable inherent complexity due to the large number of combinations of objects and processes for which access rights must be defined. Based on practical experiences, this paper introduces a new approach for the implementation of access control for application systems which reduces this complexity. After describing the challenges for such an approach, we introduce process spaces and object spaces as a basis for authorisations. We show how they make application security maintainable, controllable and offer sufficient flexibility for reaction to changing business needs. In addition, we discuss how a separation of administration and access layers allows for convenient administration as well as optimised access decision performance in business-critical applications. To facilitate the integration of this rule-based concept into enterprise-wide security administration, we show how application security can be integrated into role-based access control (RBAC) systems. In particular, this goal is achieved by enhancing Enterprise RBAC (ERBAC) with variable roles. These roles can contain variable process and object spaces referencing user and role attributes. Finally, we give a short overview over related work.
机译:本文介绍了高效访问权限管理和访问控制的新概念。它侧重于应用程序安全的特殊要求,并反映了大型行业应用系统安全实施的经验。应用程序安全性显示了由于必须定义访问权限的对象和过程的大量组合而显示了相当大的固有复杂性。基于实际经验,本文介绍了一种新方法,用于实现应用系统的访问控制,这减少了这种复杂性。在描述这种方法的挑战之后,我们将过程空间和对象空间引入授权的基础。我们展示了它们如何使应用安全可维护,可控,并为不断变化的业务需求进行反应提供足够的灵活性。此外,我们讨论了管理和访问层的分离方式,允许方便的管理以及在业务关键期应用程序中优化的访问决策性能。为了促进基于规则的概念集成企业范围的安全管理,我们展示了应用程序安全如何集成到基于角色的访问控制(RBAC)系统中。特别是,通过使用可变角色增强企业RBAC(ERBAC)来实现这一目标。这些角色可以包含引用用户和角色属性的可变进程和对象空间。最后,我们提供了与相关工作的简短概览。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号