【24h】

Access Control for an Organization Connected by Insecure Public Networks

机译:通过不安全的公共网络连接的组织的访问控制

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

An organization may divide its subjects and objects into different groups. Each group has different security clearance or level. In order to prevent sensitive information accessed by irrelevant users, an access control policy is defined to specify the eligible information flows among groups. If the organization is within a secure private network, either access control lists attached on objects or capability lists attached on subjects are enough to regulate information flows. However, for an organization with different sites connected by insecure public networks, a trusted third party may be necessary to act as an authorization/authentication server. The functionality of this server is to provide authorization and authentication services, and possibly to distribute a session key to protect data during transmission. Kerberos is a typical system that provides these services in a network using a trusted third party. In Kerberos, every communication session between two parties needs to get an access ticket from the server first. This is not efficient in the sense that a two-way communication needs a three-way communication effort. This paper proposes a key assignment scheme to enforce access control policies of an organization connected by insecure public networks without the involvement of any trusted third party. As a result, the efficiency could be enhanced tremendously.
机译:组织可以将其主题和对象划分为不同的组。每个组具有不同的安全许可或级别。为了防止无关用户访问敏感信息,定义了访问控制策略以指定组之间的合格信息流。如果组织位于安全的专用网络中,则对象上附加的访问控制列表或主题上附加的功能列表就足以规范信息流。但是,对于具有通过不安全公共网络连接的不同站点的组织,可能需要受信任的第三方充当授权/身份验证服务器。该服务器的功能是提供授权和身份验证服务,并可能分发会话密钥以在传输期间保护数据。 Kerberos是一种典型的系统,它使用受信任的第三方在网络中提供这些服务。在Kerberos中,两方之间的每个通信会话都需要首先从服务器获取访问票证。在双向通信需要三路通信努力的意义上,这是无效的。本文提出了一种密钥分配方案,以强制实施由不安全的公共网络连接的组织的访问控制策略,而无需任何受信任的第三方的参与。结果,可以极大地提高效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号