首页> 外文会议>Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy >Refresh Instead of Revoke Enhances Safety and Availability: A Formal Analysis
【24h】

Refresh Instead of Revoke Enhances Safety and Availability: A Formal Analysis

机译:刷新而不是撤销提高安全性和可用性:正式分析

获取原文

摘要

Due to inherent delays and performance costs, the decision point in a distributed multi-authority Attribute-Based Access Control (ABAC) system is exposed to the risk of relying on outdated attribute values and policy; which is the safety and consistency problem. This paper formally characterizes three increasingly strong levels of consistency to restrict this exposure. Notably, we recognize the concept of refreshing attribute values rather than simply checking the revocation status, as in traditional approaches. Refresh replaces an older value with a newer one, while revoke simply invalidates the old value. Our lowest consistency level starts from the highest level in prior revocation-based work by Lee and Winslett (LW). Our two higher levels utilize the concept of request time which is absent in LW. For each of our levels we formally show that using refresh instead of revocation provides added safety and availability.
机译:由于固有的延迟和性能成本,分布式多权力属性的访问控制(ABAC)系统中的决策点暴露于依赖过时的属性值和策略的风险;这是安全和一致性问题。本文正式地表征了三个越来越强的一致性,以限制这种暴露。值得注意的是,我们认识到刷新属性值的概念,而不是简单地检查撤销状态,如传统方法。刷新替换较新的值,revoke只是使旧值无效。我们最低一致性级别从李和Winslett(LW)以前撤销的工作中最高级别开始。我们的两个较高级别利用LW中不存在的请求时间概念。对于我们的每个级别,我们正式表明使用刷新而不是撤销提供了额外的安全性和可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号