首页> 外文会议>International Conference on Secure IT Systems >A Mechanism for Identity Delegation at Authentication Level
【24h】

A Mechanism for Identity Delegation at Authentication Level

机译:身份授权在身份验证级别的机制

获取原文

摘要

Authentication and access control are normally considered as separate security concepts that have separate goals and are supported by separate security mechanisms. In most operating systems, however, access control is exclusively based on the identity of the requesting principal, e.g., an access control mechanism based on access control lists simply verifies that the authenticated identity of the requesting principal is on the list of authorized users. In this paper we propose a human-to-human delegation mechanism for nomadic users, which exploits the amalgamation of authentication and access control in most operating systems, by delegating privileges at the identity level. The complexity of classic delegation models, especially if they strictly follow the principle of least privileges, often leads to a poor usability, which motivates a user to circumvent the default delegation mechanism. On the other hand, the identity delegation makes good use of trust relationships among users of a particular environment and offers the possibility of improved usability. Although identity delegation might violate the principle of least privileges, in practice it could increase the over all security of a nomadic environment where users need to delegate their duties frequently. The proposed mechanism is independent of the access control and the delegation event is only logged at the authentication level. Due to its improved usability, the motivation to share authentication tokens is reduced.
机译:身份验证和访问控制通常被视为具有单独目标的单独安全概念,并由单独的安全机制支持。然而,在大多数操作系统中,访问控制专门基于请求主体的标识,例如,基于访问控制列表的访问控制机制简单地验证请求主体的经过身份验证的身份在授权用户列表中。在本文中,我们提出了一种用于游牧民族用户的人对人为代表性机制,该机制利用在大多数操作系统中利用对最验证和访问控制的融合,通过委派身份级别。经典委派模型的复杂性,特别是如果他们严格遵循最小权限的原则,通常会导致可用性差,这激励用户规避默认委派机制。另一方面,身份代表团良好地利用特定环境的用户之间的信任关系,并提供了改善可用性的可能性。虽然身份代表团可能违反最小特权的原则,但实际上,它可能会增加用户需要经常委托其职责的游牧环境的所有安全性。所提出的机制独立于访问控制,委托事件仅在身份验证级别记录。由于其可用性提高,分享认证令牌的动机减少了。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号