【24h】

A generalized context-based access control model for pervasive environments

机译:适用于普适环境的通用基于上下文的访问控制模型

获取原文
获取原文并翻译 | 示例

摘要

Pervasive Computing Environments enable new opportunities for users to share and to access resources anytime and anywhere in a more natural way, making access control a critical issue. These heterogeneous and dynamic sensor-rich environments characterized by frequent and unpredictable changes on user's, resource's, and environment situations, call for access control solutions that allow dynamically adjust access permissions based on information describing the conditions of these entities (context), such as location and time. Some research attempts have been done based on existing models, which context information is used as an optional attribute for limiting the scope of access control permissions. However, these approaches normally exploit identities and roles dynamically assigned to the users in order to grant access permissions, which is an inappropriate solution for open and dynamic environments which we cannot assume the existence of predefined roles and user-role associations. In this scenario, we claim that access permissions should be assigned to the users only based on context information characterizing the three most important entities of any access control framework: owners, requestors, and resources. Thus, this paper proposes a generalized context-based access control model for making access control decisions completely based on context information.
机译:普适计算环境为用户提供了新的机会,使他们可以以更自然的方式随时随地共享和访问资源,这使访问控制成为一个关键问题。这些以传感器,资源和环境状况频繁且不可预测的变化为特征的异构且动态传感器丰富的环境,要求访问控制解决方案能够根据描述这些实体(上下文)状况的信息(例如位置)动态调整访问权限和时间。已基于现有模型进行了一些研究尝试,其中上下文信息用作限制访问控制权限范围的可选属性。但是,这些方法通常利用动态分配给用户的身份和角色来授予访问权限,这对于开放和动态环境是不合适的解决方案,因为我们不能假设存在预定义的角色和用户角色关联。在这种情况下,我们声称仅应基于表征任何访问控制框架的三个最重要实体(所有者,请求者和资源)的上下文信息,将访问权限分配给用户。因此,本文提出了一种基于上下文的通用访问控制模型,用于完全基于上下文信息做出访问控制决策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号