首页> 外文学位 >Automated trust establishment in open systems.
【24h】

Automated trust establishment in open systems.

机译:在开放系统中自动建立信任。

获取原文
获取原文并翻译 | 示例

摘要

Global competitive pressures and the possibility of severe security breaches are forcing organizations and individuals to develop the ability to rapidly form relationships and cooperate to solve urgent problems. Such cooperation often involves unanticipated resource sharing across organizational boundaries. As disparate groups attempt to collaborate to conduct sensitive processes and respond to problems, their efforts to provide efficient response are hindered by traditional approaches to access control. Organizations and individuals require nimble security facilities that will enable them to rapidly and efficiently access each other's resources, while offering specific privacy guarantees.; Automated trust negotiation (ATN) is a new approach to access control in open, flexible systems. ATN enables open computing by assigning an access control policy to each resource that is to be made accessible to “outsiders”. An access control policy describes the properties of the parties allowed to access that resource, in contrast to the traditional approach of listing their identities. Party's properties are demonstrated through the use of digital credentials, which often contain sensitive information about their owners. Thus their disclosure is also protected by access control policies. Since each negotiating party may have policies that the other needs to satisfy, trust is established gradually through bilateral disclosures of credentials.; The successful deployment of ATN requires resolution of many challenging issues. This thesis focuses on two key problems of ATN: negotiation strategies and sensitive information protection. Different parties might have different requirements for how much computation they are willing to do, how freely they disclose resources, and other strategic decisions. For such decisions, each party relies on its negotiation strategies. We identify necessary and sufficient conditions to guarantee interoperability between different strategies, and present a large set of mutually interoperable strategies, which provides users with maximal flexibility in choosing strategies, while still guaranteeing that a negotiation will succeed if at all possible.; Without proper protection, an access control policy itself might reveal sensitive information unintentionally. To remedy this problem, we propose a unified scheme for resource protection in ATN. This scheme treats policies as first-class resources, which can themselves be protected by policies. This provides great flexibility in expressing fine-grained access control requirements for trust negotiation.
机译:全球竞争压力和严重违反安全性的可能性正迫使组织和个人发展迅速建立关系并合作解决紧急问题的能力。这种合作通常涉及跨组织边界的意外资源共享。当不同的团体试图合作进行敏感的过程并响应问题时,他们提供有效响应的努力受到传统的访问控制方法的阻碍。组织和个人需要灵活的安全设施,使他们能够快速有效地访问彼此的资源,同时提供特定的隐私保证。自动信任协商(ATN)是一种开放,灵活的系统中访问控制的新方法。 ATN通过为要使“外部人员”访问的每个资源分配访问控制策略来启用开放计算。与列出身份的传统方法相反,访问控制策略描述了被允许访问该资源的各方的 properties 。政党的财产通过使用数字证书来证明,该证书通常包含有关其所有者的敏感信息。因此,它们的公开也受到访问控制策略的保护。由于每个谈判方可能都有对方需要满足的政策,因此通过双边公开证书逐渐建立信任。 ATN的成功部署需要解决许多具有挑战性的问题。本文重点研究了ATN的两个关键问题:协商策略和敏感信息保护。各方可能对自己愿意进行多少计算,如何自由地披露资源以及其他战略决策有不同的要求。对于此类决定,各方都依赖于其谈判策略。我们确定了必要条件和充分条件,以保证不同策略之间的互操作性,并提出了一大套相互可互操作的策略,这为用户提供了最大的选择策略的灵活性,同时仍然保证谈判将尽可能成功。没有适当的保护,访问控制策略本身可能会无意间泄露敏感信息。为了解决这个问题,我们提出了一个统一的ATN资源保护方案。该方案将策略视为一流的资源,它们本身可以受到策略的保护。这为表达信任协商的细粒度访问控制要求提供了极大的灵活性。

著录项

  • 作者

    Yu, Ting.;

  • 作者单位

    University of Illinois at Urbana-Champaign.;

  • 授予单位 University of Illinois at Urbana-Champaign.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2003
  • 页码 185 p.
  • 总页数 185
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号