首页> 外文会议>Microwave Symposium Digest, 2005 >Cassandra: distributed access control policies with tunable expressiveness
【24h】

Cassandra: distributed access control policies with tunable expressiveness

机译:Cassandra:具有可调节表达性的分布式访问控制策略

获取原文
获取原文并翻译 | 示例

摘要

We study the specification of access control policy in large-scale distributed systems. Our work on real-world policies has shown that standard policy idioms such as role hierarchy or role delegation occur in practice in many subtle variants. A policy specification language should therefore be able to express this variety of features smoothly, rather than add them as specific features in an ad hoc way, as is the case in many existing languages. We present Cassandra, a role-based trust management system with an elegant and readable policy specification language based on Datalog with constraints. The expressiveness (and computational complexity) of the language can be adjusted by choosing an appropriate constraint domain. With just five special predicates, we can easily express a wide range of policies including role hierarchy, role delegation, separation of duties, cascading revocation, automatic credential discovery and trust negotiation. Cassandra has a formal semantics for query evaluation and for the access control enforcement engine. We use a goal-oriented distributed policy evaluation algorithm that is efficient and guarantees termination. Initial performance results for our prototype implementation have been promising.
机译:我们研究大型分布式系统中访问控制策略的规范。我们对现实世界政策的研究表明,实际上,标准的政策惯用法(例如角色层次结构或角色委派)以许多微妙的形式出现。因此,策略规范语言应该能够平稳地表达各种功能,而不是像许多现有语言那样以临时的方式将它们添加为特定功能。我们介绍Cassandra,这是一个基于角色的信任管理系统,具有基于Datalog的具有约束力的优雅且易读的策略规范语言。可以通过选择适当的约束域来调整语言的表达性(和计算复杂性)。仅需五个特殊谓词,我们就可以轻松表达各种策略,包括角色层次结构,角色委派,职责分离,级联吊销,自动凭证发现和信任协商。 Cassandra具有用于查询评估和访问控制实施引擎的形式语义。我们使用高效且保证终止的面向目标的分布式策略评估算法。我们的原型实施的初步性能结果令人鼓舞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号