首页> 外文学位 >Expressive Power, Safety and Cloud Implementation of Attribute and Relationship Based Access Control Models
【24h】

Expressive Power, Safety and Cloud Implementation of Attribute and Relationship Based Access Control Models

机译:基于属性和关系的访问控制模型的表现力,安全性和云实现

获取原文
获取原文并翻译 | 示例

摘要

For the last few years Attribute Based Access Control (ABAC) has been emerging as the next dominant form of access control. According to a 2014 NIST special publication, "ABAC enables more precise access control model as it can consider numerous attributes in authorization decision." ABAC can unify the advantages of the traditional discretionary, mandatory and role-based access control models by using appropriate attributes, while going beyond the capabilities of these. ABAC has become recognized as a model expressive enough to define finer-grained and flexible authorization policies suitable for modern application domains such cloud computing and Internet of Things. Meanwhile, in recent years, various online social network (OSN) applications such as Facebook, Twitter and LinkedIn have become widely used. In OSNs, authorization for users' access to specific content is typically based on the interpersonal relationships between the accessing user and content owner. Recently ReBAC has been expanded to cover systems beyond OSNs. Efforts to combine ReBAC and ABAC have also been published.;This dissertation makes fundamental contributions to our understanding of ABAC and ReBAC from three perspectives. Firstly, it clarifies and resolves conflicting claims in the literature regarding the expressive power of ABAC and ReBAC. It has been argued, on one hand, that attributes can encode relationships so ABAC subsumes ReBAC. On the other hand, it has been claimed that the multilevel or composed relations of ReBAC (such as friend of friend) bring fundamentally new capabilities. This dissertation develops separate classifications of ABAC and ReBAC models with respect to salient structural and dynamic properties. It shows the equivalence, dominance or non-comparability of the expressive power of various model classes in these classifications. The results of this analysis show that ABAC and ReBAC, when defined with sufficient generality, are equivalent in expressive power. For less general forms of ABAC and ReBAC the relative expressive power depends strongly on the details of the respective models.;Secondly, this dissertation analyzes the safety and expressive power of an existing ABAC model, viz. ABACalpha. ABACalpha is designed with just sufficient capabilities to configure commonly used forms of discretionary, mandatory and role-based access control. In particular ABACalpha restricts attribute values to be from finite fixed domains. The safety analysis of ABACalpha is shown to be decidable by providing a reduction from ABACalpha to safety decidable UCON (finite)/(preA) with finite attribute domain, which is a structurally different ABAC model with finite fixed domains. Two enhanced versions of ABACalpha are defined. One of these is shown to be equivalent in expressive power to UCON (finite)/(preA) with finite attribute domain. The other is shown to have undecidable safety and thus expressive power beyond UCON (finite)/(preA) with finite attribute domain. The question of whether ABACalpha is strictly less expressive than UCON (finite)/(preA) with finite attribute domain or equivalent to it, is left open.;Finally, the dissertation introduces a novel form of ReBAC model (OOReBAC) considering object-to-object relationship independent of users to control access of resources. A proof-of-concept implementation of OOReBAC for multicloud resource sharing using the open source OpenStack cloud platform and specifically its Swift object storage service is provided.
机译:在过去的几年中,基于属性的访问控制(ABAC)已经成为访问控制的下一个主要形式。根据2014年NIST的特殊出版物,“ ABAC支持更精确的访问控制模型,因为它可以在授权决策中考虑众多属性。” ABAC可以通过使用适当的属性来统一传统的,基于权限的,强制性的和基于角色的访问控制模型的优势,同时超越这些功能的范围。 ABAC已被公认为足以表达的模型,可以定义适合现代应用程序域(如云计算和物联网)的更细粒度和灵活的授权策略。同时,近年来,诸如Facebook,Twitter和LinkedIn的各种在线社交网络(OSN)应用已被广泛使用。在OSN中,对用户访问特定内容的授权通常基于访问用户与内容所有者之间的人际关系。最近,ReBAC已扩展到涵盖OSN以外的系统。结合ReBAC和ABAC的努力也已经发表。;本论文从三个角度为我们对ABAC和ReBAC的理解做出了基础性的贡献。首先,它澄清并解决了有关ABAC和ReBAC的表达能力的文献中相互矛盾的主张。一方面,有人争辩说属性可以编码关系,所以ABAC包含ReBAC。另一方面,据称ReBAC的多层次或组合关系(例如,朋友的朋友)从根本上带来了新的功能。本文针对结构和动力学特性,分别建立了ABAC和ReBAC模型的分类。它显示了这些分类中各种模型类别的表达能力的等效性,优势性或不可比性。分析结果表明,ABAC和ReBAC在具有足够的通用性时,在表达能力上是等效的。对于ABAC和ReBAC的一般形式,其相对表达能力主要取决于各自模型的细节。其次,本文分析了现有ABAC模型的安全性和表达能力。 ABACalpha。 ABACalpha的设计仅具有足够的功能,可以配置惯用的,强制性的和基于角色的访问控制的常用形式。特别地,ABACalpha将属性值限制为来自有限的固定域。通过提供从ABACalpha到具有有限属性域的安全可确定UCON(finite)/(preA)的还原,可以证明ABACalpha的分析是可以确定的,这是结构上具有固定固定域的ABAC模型。定义了ABACalpha的两个增强版本。在具有有限属性域的UCON(有限)/(preA)的表达能力上,它们之一被证明是等效的。另一个具有不确定的安全性,因此具有超出UCON(有限)/(preA)和有限属性域的表达能力。 ABACalpha是否严格小于具有有限属性域的UCON(finite)/(preA)或与之等效的问题尚待解决。最后,本文介绍了一种新颖的ReBAC模型(OOReBAC),该模型考虑了对象到-对象关系独立于用户以控制资源的访问。提供了使用开放源代码OpenStack云平台(特别是其Swift对象存储服务)的OOReBAC进行多云资源共享的概念验证实现。

著录项

  • 作者

    Ahmed, Tahmina.;

  • 作者单位

    The University of Texas at San Antonio.;

  • 授予单位 The University of Texas at San Antonio.;
  • 学科 Computer science.;Information technology.
  • 学位 Ph.D.
  • 年度 2017
  • 页码 137 p.
  • 总页数 137
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号