首页> 外文学位 >Access control for the Web via proof-carrying authorization.
【24h】

Access control for the Web via proof-carrying authorization.

机译:通过带有证据的授权对Web进行访问控制。

获取原文
获取原文并翻译 | 示例

摘要

After a short period of being not much more than a curiosity, the World-Wide Web quickly became an important medium for discussion, commerce, and business. Instead of holding just information that the entire world could see, web pages also became used to access email, financial records, and other personal or proprietary data that was meant to be viewed only by particular individuals or groups. This made it necessary to design mechanisms that would restrict access to web pages. Unfortunately, most current mechanisms are lacking in generality and flexibility—they interoperate poorly and can express only a limited number of security policies.; We view access control on the web as a general distributed authorization problem and develop a solution by adapting the techniques of proof-carrying authorization, a framework for defining security logics based on higher-order logic.; In this dissertation we present a particular logic for modeling access-control scenarios that occur on the web. We give this application-specific logic a semantics in higher-order logic, thus ensuring its soundness, and use it to implement a system that regulates access to web pages. Our system uncouples authorization from authentication, allowing for better interoperation across administrative domains and more expressive security policies. Our implementation consists of a web server module and a local web proxy. The server allows access to pages only if the web browser can demonstrate that it is authorized to view them. The browser's local proxy accomplishes this by mechanically constructing a proof of a challenge sent to it by the server. Our system supports arbitrarily complex delegation, and we implement a framework that lets the web browser locate and use pieces of the security policy that have been distributed across arbitrary hosts. Our system was built for controlling access to web pages, but could relatively easily be extended to encompass access control for other applications as well.
机译:在短短的好奇心之后,万维网迅速成为讨论,商业和商务的重要媒介。网页不仅保留了整个世界可以看到的信息,还被用来访问电子邮件,财务记录以及其他本应仅由特定个人或团体查看的个人或专有数据。这使得必须设计出限制访问网页的机制。不幸的是,当前大多数机制缺乏通用性和灵活性,它们互操作性差,并且只能表示有限数量的安全策略。我们将Web上的访问控制视为一个普遍的分布式授权问题,并通过调整携带证明的授权技术来开发解决方案,该方法是基于高阶逻辑定义安全性逻辑的框架。在本文中,我们提出了一种用于对Web上发生的访问控制方案进行建模的特定逻辑。我们为该特定于应用程序的逻辑赋予高阶逻辑语义,从而确保其合理性,并使用它来实现规范访问网页的系统。我们的系统将授权与身份验证脱钩,从而可以在管理域之间实现更好的互操作性,并实现更具表现力的安全策略。我们的实现包括一个Web服务器模块和一个本地Web代理。仅当Web浏览器可以证明其有权查看页面时,服务器才允许访问页面。浏览器的本地代理通过机械构造服务器发送给它的质询证明来实现此目的。我们的系统支持任意复杂的委托,并且我们实现了一个框架,该框架使Web浏览器可以定位和使用已分布在任意主机上的安全策略。我们的系统是为控制对网页的访问而构建的,但是可以相对容易地扩展为涵盖其他应用程序的访问控制。

著录项

  • 作者

    Bauer, Ljudevit.;

  • 作者单位

    Princeton University.;

  • 授予单位 Princeton University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2003
  • 页码 124 p.
  • 总页数 124
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号