首页> 外文会议>Microwave Symposium Digest, 2005 >Responding to policies at runtime in TrustBuilder
【24h】

Responding to policies at runtime in TrustBuilder

机译:在TrustBuilder中在运行时响应策略

获取原文
获取原文并翻译 | 示例

摘要

Automated trust negotiation is the process of establishing trust between entities with no prior relationship through the iterative disclosure of digital credentials. One approach to negotiating trust is for the participants to exchange access control policies to inform each other of the requirements for establishing trust. When a policy is received at run-time, a compliance checker determines which credentials satisfy the policy so they can be disclosed. In situations where severed sets of credentials satisfy a policy and some of the credentials are sensitive, a compliance checker that generates all the sets is necessary to insure that the negotiation succeeds whenever possible. Compliance checkers designed for trust management do not usually generate all the satisfying sets. In this paper, we present two practical algorithms for generating all satisfying sets given a compliance checker that generates only one set. The ability to generate all of the combinations provides greater flexibility in how the system or user establishes trust. For example, the least sensitive credential combination could be disclosed first. These Ideas have been implemented in TrustBuilder, our prototype system for trust negotiation.
机译:自动化信任协商是通过迭代公开数字证书在没有先验关系的实体之间建立信任的过程。协商信任的一种方法是让参与者交换访问控制策略,以相互告知建立信任的要求。当在运行时收到策略时,合规性检查器将确定哪些凭据满足该策略,以便将其公开。在切断的凭证集满足策略且某些凭证敏感的情况下,必须生成所有凭证集的合规性检查器,以确保在任何可能的情况下协商都能成功。专为信任管理而设计的合规检查器通常不会生成所有令人满意的集合。在本文中,我们给出了两种实用算法,用于生成给定的一致性检查程序仅生成一个集合的所有令人满意的集合。生成所有组合的能力为系统或用户建立信任的方式提供了更大的灵活性。例如,可以首先公开最不敏感的凭证组合。这些想法已在TrustBuilder(我们用于信任协商的原型系统)中实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号