首页> 外文会议>International Conference on Data Management Technologies and Applications >Hypergraph-based Access Control using Formal Language Expressions - HGAC
【24h】

Hypergraph-based Access Control using Formal Language Expressions - HGAC

机译:基于超图的访问控制使用正式语言表达式 - HGAC

获取原文

摘要

In all organizations, access assignments are essential in order to ensure data privacy, permission levels and the correct assignment of tasks. Traditionally, such assignments are based on total enumeration, with the consequence that constant effort has to be put into maintaining the assignments. This problem still persists when using abstraction layers, such as group and role concepts, e.g. Access Control Matrix and Role-Based Access Control. Role and group memberships are statically defined and members have to be added and removed constantly. This paper describes a novel approach - Hypergraph-Based Access Control HGAC - to assign human and automatic subjects to access rights in a declarative manner. The approach is based on an organizational (meta-) model and a declarative language. The language is used to express queries and formulate predicates. Queries define sets of subjects based on their properties and their position in the organizational model. They also contain additional information that causes organizational relations to be active or inactive depending on predicates. In HGAC, the subjects that have a specific permission are determined by such a query. The query itself is not defined statically but created by traversing a hypergraph path. This allows a structured aggregation of permissions on resources. Consequently, multiple resources can share parts of their queries.
机译:在所有组织中,访问分配至关重要,以确保数据隐私,权限级别和正确分配任务。传统上,这种作业基于总枚举,结果必须努力维护任务。使用抽象层时,此问题仍然存在,例如组和角色概念,例如,访问控制矩阵和基于角色的访问控制。静态定义角色和组成员资格,并且必须不断添加和删除成员。本文介绍了一种新颖的方法 - 基于超图的访问控制HGAC - 以声明方式分配人员和自动受试者访问权限。该方法基于组织(Meta-)模型和陈述语言。语言用于表达查询并制定谓词。查询根据其属性及其在组织模型中的位置定义一组主题。它们还包含其他信息,这些信息由于谓词而导致组织关系处于活动状态或无效。在HGAC中,具有特定许可的受试者由这种查询确定。查询本身未静态定义,而是通过遍历超图路径来创建。这允许对资源的权限进行结构化聚合。因此,多个资源可以共享其查询的一部分。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号