首页> 外文期刊>ACM Transaction on Information and System Security >Access Control Policy Translation, Verification, and Minimization within Heterogeneous Data Federations
【24h】

Access Control Policy Translation, Verification, and Minimization within Heterogeneous Data Federations

机译:异构数据联合中的访问控制策略转换,验证和最小化

获取原文
获取原文并翻译 | 示例

摘要

Data federations provide seamless access to multiple heterogeneous and autonomous data sources pertaining to a large organization. As each source database defines its own access control policies for a set of local identities, enforcing such policies across the federation becomes a challenge. In this article, we first consider the problem of translating existing access control policies defined over source databases in a manner that allows the original semantics to be observed while becoming applicable across the entire data federation. We show that such a translation is always possible, and provide an algorithm for automating the translation. We show that verifying whether a translated policy obeys the semantics of the original access control policy defined over a source database is intractable, even under restrictive scenarios. We then describe a practical algorithmic framework for translating relational access control policies into their XML equivalent, expressed in the extensible Access Control Markup Language. Finally, we examine the difficulty of minimizing translated policies, and contribute a minimization algorithm applicable to nonrecursive translated policies.
机译:数据联合会提供对涉及大型组织的多个异构和自治数据源的无缝访问。当每个源数据库为一组本地身份定义其自己的访问控制策略时,在整个联盟中强制实施此类策略就成为了挑战。在本文中,我们首先考虑转换源数据库上定义的现有访问控制策略的问题,该策略应允许观察原始语义,同时又适用于整个数据联合。我们证明了这种翻译始终是可能的,并提供了自动翻译的算法。我们证明,即使在限制性情况下,验证转换后的策略是否遵守在源数据库上定义的原始访问控制策略的语义也是很难的。然后,我们描述了一种实用的算法框架,用于将关系访问控制策略转换为以可扩展的访问控制标记语言表示的XML等效项。最后,我们研究了最小化翻译策略的困难,并提出了适用于非递归翻译策略的最小化算法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号