首页> 外文会议>MV Paper Cables: Asset or Liability? >Enforcing policies in pervasive environments
【24h】

Enforcing policies in pervasive environments

机译:在普遍环境中执行策略

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

This work presents an architecture and a proof of concept implementation of a security infrastructure for mobile devices in an infrastructure based pervasive environment. The security infrastructure primarily consists of two parts, the policy engine and the policy enforcement mechanism. Each mobile device within a pervasive environment is equipped with its own policy enforcement mechanism and is responsible for protecting its resources. A mobile device consults the nearest policy server, notifies its current state including its present user, network presence, other accessible devices and location information if available. Using this information the policy server queries the "Rei" engine to dynamically create a policy certificate and issues it to the requesting device. The system wide policy is described in a semantic language "Rei", a lightweight and extensible language which is able to express comprehensive policies using domain specific information. The "Rei" policy engine is able to dynamically decide what rights, prohibitions, obligations, dispensations an actor has on the domain actions. A policy certificate is created and issued to the device. The policy certificate contains a set of granted permissions and a validity period and scope within which the permissions are valid. The policy certificate can be revoked by the policy enforcer based on expiration of the validity period or a combination of timeout, loss of contact with an assigned network. X.509 based public key infrastructure is used to provide identification and authentication.
机译:这项工作提出了在基于基础架构的普遍环境中用于移动设备的安全基础架构的体系结构和概念验证的实现。安全基础结构主要由两部分组成,即策略引擎和策略执行机制。普遍环境中的每个移动设备都配备有自己的策略执行机制,并负责保护其资源。移动设备查询最近的策略服务器,并通知其当前状态,包括其当前用户,网络状态,其他可访问设备以及位置信息(如果可用)。策略服务器使用此信息查询“ Rei”引擎以动态创建策略证书,并将其颁发给发出请求的设备。系统范围的策略以语义语言“ Rei”描述,这是一种轻量级且可扩展的语言,能够使用特定于域的信息来表达全面的策略。 “ Rei”策略引擎能够动态地确定参与者对域操作具有哪些权利,禁止,义务,分配。创建策略证书并将其颁发给设备。策略证书包含一组已授予的权限以及有效期和有效期内的范围。策略执行者可以根据有效期届满或超时,失去与指定网络的联系的组合来撤消策略证书。基于X.509的公钥基础结构用于提供标识和身份验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号