【24h】

Improving Access Control for Mobile Consumers of Services by Use of Context and Trust within the Call-Stack

机译:通过在调用堆栈中使用上下文和信任来改善服务的移动消费者的访问控制

获取原文

摘要

Access control is a key issue in the deployment of systems within corporations. To comply with legal and business requirements and to prevent unauthorized access, the identification and authentication of all users is required. This is typically achieved by using an access control system that performs the identification & authentication of each user at the point of entry into the system. However, as the systems evolve and thus become more complex it is difficult to ensure reliable access control, especially if they are accessed via mobile devices. This paper focuses on improving the existing access control approach for service-oriented systems by applying the concept of device comfort to service providers. Similar to the concept of device comfort, service providers are empowered to decide if they feel comfortable with requests sent to them. This paper presents and evaluates the idea of integrating trust evaluations into service-oriented systems by requiring each service provider to evaluate the trustworthiness of requests and to share their evaluations as part of the call-context within the call-stack.
机译:访问控制是公司内部系统部署中的关键问题。为了遵守法律和业务要求并防止未经授权的访问,需要对所有用户进行标识和认证。通常,这是通过使用访问控制系统来实现的,该系统在进入系统时对每个用户进行标识和认证。但是,随着系统的发展并因此变得更加复杂,很难确保可靠的访问控制,尤其是如果通过移动设备访问它们时。本文致力于通过将设备舒适性的概念应用于服务提供商来改进面向服务系统的现有访问控制方法。与设备舒适度的概念类似,服务提供商有权决定是否对发送给他们的请求感到舒适。本文提出并评估了将信任评估集成到面向服务的系统中的想法,方法是要求每个服务提供者评估请求的可信赖性,并在调用堆栈内作为调用上下文的一部分共享其评估。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号