首页> 外文会议>International Conference on Digital Information Management >X-STROWL: A generalized extension of XACML for context-aware spatio-temporal RBAC model with OWL
【24h】

X-STROWL: A generalized extension of XACML for context-aware spatio-temporal RBAC model with OWL

机译:X-STROWL:XACML的广义扩展与猫头鹰的上下文感知的时空RBAC模型

获取原文

摘要

The rapid growth of location-based applications, geographic or large scale information systems has resulted in the demand of strictly controlling data access that requires specifying and enforcing fine grained policies with the variety of context-aware spatial and temporal restrictions. Besides, the interoperable use of distributed and heterogeneous data such as data sharing, data integration or data exchanging between different organizations has caused the formation and development of access control mechanisms using XML for enforcing security rules and policies in accordance with the international standards. In this paper, we propose an extension of XACML called the X-STROWL model for a generalized context-aware role-based access control (RBAC) model with the support of spatio-temporal restrictions and in conformity with the NIST standard for RBAC. In doing this, the XACML architecture is augmented with new functions and data types. In addition, policies are reorganized to adopt with the NIST standard. Besides, a set of conditions aimed to a certain circumstance can be generalized into a context profile and specified in the access control policies. The model also integrates the OWL ontology for semantic reasoning on hierarchical roles to simplify the specification of access control policies and increase the intelligence of the authorization decision engine.
机译:基于位置的应用程序,地理或大规模信息系统的快速增长导致严格控制数据访问的需求,该数据访问需要指定和执行具有各种背景感知的空间和时间限制的细粒度策略。此外,互操作性使用分布式和异构数据,如数据共享,数据集成或数据之间交换的数据集成,导致使用XML的访问控制机制的形成和开发,以便根据国际标准执行安全规则和策略。在本文中,我们提出了XACML的扩展,称为X-STROWL模型的X-STROWL模型,用于支持三种时空限制和符合RBAC的NIST标准。在此过程中,XACML架构以新功能和数据类型增强。此外,重组政策以采用NIST标准。此外,旨在某种情况的一系列条件可以广泛化到上下文配置文件中,并在访问控制策略中指定。该模型还将OWL本体集成在分层角色上的语义推理,以简化访问控制策略的规范,并增加授权决策引擎的智能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号