首页> 外文会议>International Conference on Information Systems Security >Authorization Policy Specification and Enforcement for Group-Centric Secure Information Sharing
【24h】

Authorization Policy Specification and Enforcement for Group-Centric Secure Information Sharing

机译:针对性化的安全信息共享的授权策略规范和强制执行

获取原文

摘要

In this paper, we propose a methodology for incremental security policy specification at varying levels of abstraction while maintaining strict equivalence with respect to authorization state. We specifically consider the recently proposed group-centric secure information sharing (g-SIS) domain. The current specification for g-SIS authorization policy is stateless in the sense that it solely focuses on specifying the precise conditions under which authorization can hold in the system while only considering the history of actions that have occurred. The stateless application policy has been specified using linear temporal logic. In this paper, we develop an enforceable specification that is stateful in the sense that it is defined using specific data structures that are maintained in each state so as to make authorization decisions. We show that the stateful specification is authorization equivalent to that of stateless. That is, in any state, authorization will hold in stateful if and only if it also holds in the stateless specification.
机译:在本文中,我们提出了一种在不同级别抽象级别的增量安全策略规范的方法,同时保持对授权状态的严格等价。我们特别考虑最近提出的以集体为中心的安全信息共享(G-SIS)域。 G-SIS授权策略的当前规范在某种意义上是无状态,因为它仅关注指定授权在系统中可以持有的精确条件,同时只考虑发生的操作历史。使用线性时间逻辑指定了无状态应用程序策略。在本文中,我们开发了可执行规范,这些规范是有性的,即使用每个状态维护的特定数据结构来定义它以便进行授权决策。我们表明,有状态规范是相当于无状态的规范。也就是说,在任何状态下,授权将在某个状态下持有,如果它还持有无状态规范。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号