...
首页> 外文期刊>ACM Transaction on Information and System Security >Toward a Usage-Based Security Framework for Collaborative Computing Systems
【24h】

Toward a Usage-Based Security Framework for Collaborative Computing Systems

机译:面向基于计算的协作计算系统安全框架

获取原文
获取原文并翻译 | 示例

摘要

Collaborative systems such as Grids provide efficient and scalable access to distributed computing capabilities and enable seamless resource sharing between users and platforms. This heterogeneous distribution of resources and the various modes of collaborations that exist between users, virtual organizations, and resource providers require scalable, flexible, and fine-grained access control to protect both individual and shared computing resources. In this article we propose a usage control (UCON) based security framework for collaborative applications, by following a layered approach with policy, enforcement, and implementation models, called the PEI framework. In the policy model layer, UCON policies are specified with predicates on subject and object attributes, along with system attributes as conditional constraints and user actions as obligations. General attributes include not only persistent attributes such as role and group memberships but also mutable usage attributes of subjects and objects. Conditions in UCON can be used to support context-based authorizations in ad hoc collaborations. In the enforcement model layer, our novel framework uses a hybrid approach for subject attribute acquisition with both push and pull modes. By leveraging attribute propagations between a centralized attribute repository and distributed policy decision points, our architecture supports decision continuity and attribute mutability of the UCON policy model, as well as obligation evaluations during policy enforcement. As a proof-of-concept, we implement a prototype system based on our proposed architecture and conduct experimental studies to demonstrate the feasibility and performance of our approach.
机译:诸如Grids之类的协作系统提供了对分布式计算功能的高效且可扩展的访问,并实现了用户与平台之间的无缝资源共享。资源的这种异构分布以及用户,虚拟组织和资源提供者之间存在的各种协作模式需要可伸缩,灵活和细粒度的访问控制,以保护单个和共享的计算资源。在本文中,我们通过遵循带有策略,实施和实现模型的分层方法(称为PEI框架),为协作应用程序提出了一个基于使用控制(UCON)的安全框架。在策略模型层中,使用主题和对象属性的谓词指定UCON策略,将系统属性作为条件约束,将用户操作作为义务。一般属性不仅包括持久性属性(例如角色和组成员身份),还包括主题和对象的可变用法属性。 UCON中的条件可用于支持临时协作中基于上下文的授权。在执行模型层中,我们新颖的框架使用混合模式来通过推和拉模式获取主题属性。通过利用集中式属性存储库和分布式策略决策点之间的属性传播,我们的体系结构支持UCON策略模型的决策连续性和属性可变性,以及策略执行期间的义务评估。作为概念验证,我们在我们提出的体系结构的基础上实现了原型系统,并进行了实验研究以证明该方法的可行性和性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号