首页> 外文学位 >An Ontology-Based Approach to Attribute Management in ABAC Environment.
【24h】

An Ontology-Based Approach to Attribute Management in ABAC Environment.

机译:ABAC环境中基于本体的属性管理方法。

获取原文
获取原文并翻译 | 示例

摘要

Attribute Based Access Control (ABAC) mechanisms have been attracting a lot of interest from the research community in recent times. This is especially because of the flexibility and extensibility it provides by using attributes assigned to subjects as the basis for access control. ABAC enables an administrator of a server to enforce access policies on the data, services and other such resources fairly easily. It also accommodates new policies and changes to existing policies gracefully, thereby making it a potentially good mechanism for implementing access control in large systems, particularly in today's age of Cloud Computing.;However management of the attributes in ABAC environment is an area that has been little touched upon. Having a mechanism to allow multiple ABAC based systems to share data and resources can go a long way in making ABAC scalable. At the same time each system should be able to specify their own attribute sets independently.;In the research presented in this document a new mechanism is proposed that would enable users to share resources and data in a cloud environment using ABAC techniques in a distributed manner. The focus is mainly on decentralizing the access policy specifications for the shared data so that each data owner can specify the access policy independent of others. The concept of ontologies and semantic web is introduced in the ABAC paradigm that would help in giving a scalable structure to the attributes and also allow systems having different sets of attributes to communicate and share resources.
机译:最近,基于属性的访问控制(ABAC)机制引起了研究界的广泛兴趣。这尤其是由于它通过使用分配给主题的属性作为访问控制的基础而提供的灵活性和可扩展性。 ABAC使服务器管理员可以相当轻松地对数据,服务和其他此类资源实施访问策略。它还可以很好地适应新策略和对现有策略的更改,从而使其成为在大型系统中实现访问控制的潜在良好机制,尤其是在当今的云计算时代。然而,ABAC环境中的属性管理已经成为一个领域。有点感动。拥有允许多个基于ABAC的系统共享数据和资源的机制,对于使ABAC具有可伸缩性很重要。同时,每个系统都应该能够独立指定其自己的属性集。;在本文档中提出的研究中,提出了一种新的机制,该机制将使用户能够使用ABAC技术以分布式方式在云环境中共享资源和数据。 。重点主要在于分散共享数据的访问策略规范,以便每个数据所有者可以独立于其他用户指定访问策略。在ABAC范式中引入了本体和语义网的概念,这将有助于为属性提供可伸缩的结构,并允许具有不同属性集的系统进行通信和共享资源。

著录项

  • 作者单位

    Arizona State University.;

  • 授予单位 Arizona State University.;
  • 学科 Computer Science.
  • 学位 M.S.
  • 年度 2014
  • 页码 54 p.
  • 总页数 54
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-17 11:53:48

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号