首页> 外文会议>International Workshop on Formal Aspects in Security and Trust >Cryptographic Enforcement of Role-Based Access Control
【24h】

Cryptographic Enforcement of Role-Based Access Control

机译:基于角色的访问控制的加密实施

获取原文

摘要

Many cryptographic schemes have been designed to enforce information flow policies. However, enterprise security requirements are often better encoded, or can only be encoded, using role-based access control policies rather than information flow policies. In this paper, we provide an alternative formulation of role-based access control that enables us to apply existing cryptographic schemes to core and hierarchical role-based access control policies. We then show that special cases of our cryptographic enforcement schemes for role-based access control are equivalent to cryptographic enforcement schemes for temporal access control and to ciphertext-policy and key-policy attribute-based encryption schemes. Finally, we describe how these special cases can be extended to support richer forms of temporal access control and attribute-based encryption.
机译:许多加密方案曾设计用于实施信息流策略。但是,企业安全要求通常更好地编码,或者只能使用基于角色的访问控制策略而不是信息流策略来编码。在本文中,我们提供了基于角色的访问控制的替代制定,使我们能够将现有的加密方案应用于基于核心和基于分层角色的访问控制策略。我们然后显示,基于角色的访问控制的加密实施方案的特殊情况相当于Cryptoction强制执行方案,用于时间访问控制和基于密文 - 策略和基于密钥策略属性的加密方案。最后,我们描述了如何扩展这些特殊情况以支持更丰富的时间访问控制和基于属性的加密形式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号