【24h】

Research on Risk Property of Access Control Policy

机译:访问控制政策风险性质研究

获取原文

摘要

There are leaks in the permission distribution and delegation for the traditional access control based on roles. By introducing the concept of risk, this study establishes an integrated theoretic framework. This paper represents access control policy and the ordering relation among roles based on risk. The concept of risk distance is proposed, which made the security of access control polices can be compared according their various risk bands. We also illuminate the basic relationship between roles. The properties and principle are proposed for the policies' delegation and reassignment based on risk. Through these properties and principle, this article proposed a method to optimize users' access control polices. It ensures the executions of policies are under the minimum risk. The risk-based method can limit the highly risky authorization and delegation. And it can improve the security of the system.
机译:基于角色的传统访问控制的许可分配和委派存在泄漏。通过引入风险概念,本研究建立了一个集成的理论框架。本文代表了基于风险的角色的访问控制策略和排序关系。提出了风险距离的概念,这使得可以根据其各种风险乐队比较访问控制杆的安全性。我们还阐明了角色之间的基本关系。基于风险的政策委派和重新分配,提出了物业和原则。通过这些属性和原理,本文提出了一种优化用户访问控制策略的方法。它确保政策的执行处于最低风险。基于风险的方法可以限制高风险的授权和代表团。它可以改善系统的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号