首页> 外文会议> >Distributed Enforcement of Sticky Policies with Flexible Trust
【24h】

Distributed Enforcement of Sticky Policies with Flexible Trust

机译:具有弹性信任的粘性策略的分布式执行

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we describe an approach to distributed enforcement of sticky policies in heterogeneous hardware and software environments. These heterogeneous environments might have differing mechanisms for attesting to their security capabilities and data sources might specify different levels of trust for different data items. Such an environment requires highly flexible policy specification and enforcement mechanisms. We employ sticky policies that travel with data wherever it travels, and we separate them into two components, a hosting policy and a usage policy. Hosting policies are used to ensure that data are transferred only to entities that are provably capable of providing local enforcement and only further transferring data under the same policies. Usage policies confer access, viewing, and update capabilities on users based on their attributes. The approach is supported by attribute-based certificates and policies, which include what authorities are trusted to certify attributes. In addition to presenting a full description of the approach, we report on a prototype implementation that includes all of the aforementioned components and also makes use of a modified version of Excel we developed to track security labels as data move through spreadsheets that are being shared by multiple users across different systems.
机译:在本文中,我们描述了一种在异构硬件和软件环境中分布式实施粘性策略的方法。这些异构环境可能具有不同的机制来证明其安全能力,并且数据源可能为不同的数据项指定不同的信任级别。这样的环境需要高度灵活的策略规范和执行机制。我们采用随行数据随行的粘性策略,并将它们分为两个部分:托管策略和使用策略。托管策略用于确保仅将数据传输到可证明能够提供本地实施的实体,并且仅在相同策略下进一步传输数据。使用策略根据用户的属性授予用户访问,查看和更新​​功能。该方法由基于属性的证书和策略支持,其中包括受信任的哪些机构可以验证属性。除了提供该方法的完整说明之外,我们还报告一个原型实现,其中包括所有上述组件,并且还利用我们开发的Excel的修改版来跟踪数据通过电子表格共享的安全标签,跨不同系统的多个用户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号