首页> 外文会议>IEEE International Symposium on Policies for Distributed Systems and Networks >Towards Session-Aware RBAC Administration and Enforcement with XACML
【24h】

Towards Session-Aware RBAC Administration and Enforcement with XACML

机译:在会话感知的RBAC管理和与XACML的执行

获取原文
获取外文期刊封面目录资料

摘要

An administrative role-based access control (ARBAC) model specifies administrative policies over a role-based access control (RBAC) system, where an administrative permission may change an RBAC policy by updating permissions assigned to roles, or assigning/revoking users to/from roles. Consequently, enforcing ARBAC policies over an active access controller while some users are using protected resources would result in conflicts: a policy may be in effect in the RBAC system while being updated by an ARBAC operation. Towards solving this concurrency problem, we propose a session-aware administrative model for RBAC. We show how the concurrency problem can be resolved by enhancing the extensible access control markup language (XACML) reference implementation. In order to do so, we develop an XACML-ARBAC profile to specify ARBAC policies, and enforce these polices by building an ARBAC enforcement module and a session administrative module. The former synchronizes with the evaluation of access control requests. The latter revokes conflicting ongoing user sessions immediately prior to enforcing administrative operations. Experimental studies show reasonable performance characteristics of our initial enhancement to Sun's reference implementation.
机译:基于管理角色的访问控制(ABBAC)模型指定了基于角色的访问控制(RBAC)系统的管理策略,其中管理权限可以通过将分配给角色的权限更新,或者将/撤销用户分配/撤销用户来更改RBAC策略角色。因此,在有关访问控制器上执行ARBAC策略,而某些用户使用受保护的资源将导致冲突:策略可能在RBAC系统中生效,同时由ABRAC操作更新。为了解决此并发问题,我们向RBAC提出了一次会话感知管理模型。我们展示如何通过增强可扩展访问控制标记语言(XACML)参考实现来解决并发问题。为此,我们开发XACML-ARBAC配置文件以指定ABAC策略,并通过构建ABAC执行模块和会话管理模块来强制执行这些策略。前者与访问控制请求的评估同步。后者撤销在执行管理操作之前立即冲突的持续用户会话。实验研究表明我们对Sun的参考实施的初步增强的合理性能特征。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号