首页> 外文会议>International Conference on Education, Management and Computing Technology >A Novel Role-Based-Access-Control(RBAC) Framework and Application
【24h】

A Novel Role-Based-Access-Control(RBAC) Framework and Application

机译:基于角色的基于角色访问控制(RBAC)框架和应用程序

获取原文

摘要

In recent time, RBAC has gained and kept a dominant stage of AC (access control) in the research area and industry, respectively. Over the time, needs for risk awareness in AC has paid special attention. Even though, role based access control conquers risk via inner features, a quantified method of risk awareness has been proposed as a leading and fascinating research topic due to its inherent flexibility. In this approach, risk-cost metrics are calculated for different entities involved in AC such as users and related objects and a risk threshold restricts the permissions which could be exercised. The quantified methodology arranges dynamism in access decisions procedure based on contexts-situations such as an worker accessing sensitive files through a work computer versus accessing using her own device. In this paper, we compare the difference between the traditional risk mitigation and the recent quantified risk-aware approaches in RBAC and propose a framework for introducing risk-awareness in RBAC models that incorporates quantified-risk. We also provide a formal specification of an adaptive risk-aware RBAC model by enhancing the NIST core RBAC model.
机译:近来,RBAC分别在研究区和工业中获得了一系列主导的AC(访问控制)。随着时间的推移,AC中的风险意识需要特别注意。即使,基于角色的访问控制征收风险通过内部特征,已经提出了一种量化的风险意识方法,作为其固有的灵活性导致的主要和迷人的研究主题。在这种方法中,针对诸如用户和相关对象涉及的不同实体计算风险成本度量,并且风险阈值限制了可以进行的权限。量化的方法基于诸如使用自己的设备的工作计算机访问敏感文件的工作者等上下文的情况,在访问决策过程中排列动态性。在本文中,我们比较了RBAC中传统风险减缓和最近的量化风险感知方法之间的差异,并提出了一种涉及量化风险的RBAC模型风险认识的框架。我们还通过增强NIST核心RBAC模型提供适应性风险感知RBAC模型的正式规范。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号