【24h】

The UCON_(ABC) Usage Control Model

机译:UCON_(ABC)使用控制模型

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we introduce the family of UCON_(ABC) models for usage control (UCON), which integrate Authorizations (A), oBligations (B), and Conditions (C). We call these core models because they address the essence of UCON, leaving administration, delegation, and other important but second-order issues for later work. The term usage control is a generalization of access control to cover authorizations, obligations, conditions, continuity (ongoing controls), and mutability. Traditionally, access control has dealt only with authorization decisions on users' access to target resources. Obligations are requirements that have to be fulfilled by obligation subjects for allowing access. Conditions are subject and object independent environmental or system requirements that have to be satisfied for access. In today's highly dynamic, distributed environment, obligations and conditions are also crucial decision factors for richer and finer controls on usage of digital resources. Although they have been discussed occasionally in recent literature, most authors have been motivated from specific target problems and thereby limited in their approaches. The UCON_(ABC) model integrates these diverse concepts in a unified framework. Traditional authorization decisions are generally made at the time of requests but hardly recognize ongoing controls for relatively long-lived access or for immediate revocation. Moreover, mutability issues that deal with updates on related subject or object attributes as a consequence of access have not been systematically studied. Unlike other studies that have targeted on specific problems or issues, the UCON_(ABC) model seeks to enrich and refine the access control discipline in its definition and scope. UCON_(ABC) covers traditional access controls such as mandatory, discretionary, and role-based access control. Digital rights management and other modern access controls are also covered. UCON_(ABC) lays the foundation for next generation access controls that are required for today's real-world information and systems security. This paper articulates the core of this new area of UCON and develops several detailed models.
机译:在本文中,我们介绍了用于使用控制(UCON)的UCON_(ABC)模型系列,该模型集成了授权(A),责任(B)和条件(C)。我们将这些核心模型称为“核心模型”,是因为它们解决了UCON的本质,将管理,委派和其他重要但二阶的问题留给以后的工作。术语“使用控制”是访问控制的概括,涵盖授权,义务,条件,连续性(进行中的控制)和可变性。传统上,访问控制仅处理有关用户对目标资源的访问权的授权决策。义务是义务主体必须满足的允许访问的要求。条件是访问必须满足的与主题和对象无关的环境或系统要求。在当今高度动态的分布式环境中,义务和条件对于更丰富,更精细地控制数字资源的使用也至关重要。尽管在最近的文献中偶尔对它们进行了讨论,但是大多数作者都是出于特定目标问题的动机,因此其方法受到限制。 UCON_(ABC)模型将这些不同的概念集成在一个统一的框架中。传统的授权决策通常是在请求时做出的,但是几乎不能识别持续时间较长的访问或立即撤销的持续控制。此外,尚未系统地研究与访问有关的,涉及相关主题或对象属性更新的可变性问题。与其他针对特定问题或问题的研究不同,UCON_(ABC)模型试图在其定义和范围上丰富和完善访问控制学科。 UCON_(ABC)涵盖了传统的访问控制,例如强制性,自主性和基于角色的访问控制。还涵盖了数字版权管理和其他现代访问控制。 UCON_(ABC)为当今的现实世界的信息和系统安全性所需的下一代访问控制奠定了基础。本文阐述了UCON这个新领域的核心,并开发了一些详细的模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号