...
首页> 外文期刊>Computers & Security >Security solution frames and security patterns for authorization in distributed, collaborative systems
【24h】

Security solution frames and security patterns for authorization in distributed, collaborative systems

机译:用于分布式协作系统中的授权的安全解决方案框架和安全模式

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The design of an authorization infrastructure is one of the most important aspects of engineering a secure software system. Unlike other system types, distributed systems - and especially distributed collaborative systems - can require custom, fine-grained authorization models and enforcement approaches that are able to take into account a range of semantic subtleties. In this paper we present a comprehensive, pattern-oriented software engineering approach to authorization for general distributed systems - with particular applicability to distributed collaborative systems - that allows developers to build custom, application-specific conceptual authorization models in a simple yet extensible manner, and to make informed decisions regarding their enforcement in software, as well as how their supporting rule/policy infrastructure should be designed. Our authorization approach is embodied in two instances of a new pattern-based security engineering construct called a security solution frame, which groups together related patterns - both security "product" and micro-process patterns - in different sub-structures, horizontally and vertically, for a single high-level security policy (in our case authorization and policy management). By applying specific micro-process patterns in each solution frame, developers are guided in using relevant "product" patterns to progressively construct a distributed authorization infrastructure - from abstract concepts toward concrete designs, via a number of levels of abstraction implying solution refinement and corresponding to stages of the development life-cycle. The summary-form "product" patterns encapsulated in each frame also help developers to form a holistic, "global" view when analyzing existing infrastructures. We illustrate and evaluate the proposal in the context of greenfield system development by applying our solution frames to design the authorization infrastructure of a (new) distributed system for secure file sharing and collaborative editing; and also use our solution frames to briefly analyze and capture the design decisions underlying two existing distributed authorization infrastructures: one based on UCON for collaborative Grid systems and another based on ZBAC for SOA-based systems.
机译:授权基础结构的设计是设计安全软件系统的最重要方面之一。与其他系统类型不同,分布式系统-尤其是分布式协作系统-可能需要自定义,细粒度的授权模型和实施方法,这些模型必须考虑到一系列语义上的细微差别。在本文中,我们提出了一种全面的,面向模式的软件工程方法来授权通用分布式系统-特别适用于分布式协作系统-该方法允许开发人员以简单但可扩展的方式构建定制的,特定于应用程序的概念授权模型,以及就其在软件中的执行以及应如何设计其支持规则/策略基础结构做出明智的决定。我们的授权方法体现在称为安全解决方案框架的基于模式的新安全工程构造的两个实例中,该结构将相关模式-安全“产品”和微处理模式-分为水平和垂直的不同子结构,单个高级安全策略(在我们的示例中为授权和策略管理)。通过在每个解决方案框架中应用特定的微处理模式,引导开发人员使用相关的“产品”模式逐步构建分布式授权基础结构-从抽象概念到具体设计,并通过许多抽象级别来暗示解决方案的改进,并对应于开发生命周期的各个阶段。封装在每个框架中的摘要形式的“产品”模式还可以帮助开发人员在分析现有基础结构时形成整体的“全局”视图。通过应用我们的解决方案框架设计(新的)分布式系统的授权基础结构,以进行安全文件共享和协作编辑,我们在绿地系统开发的背景下说明和评估了该提案;并使用我们的解决方案框架简要分析和捕获基于两个现有分布式授权基础结构的设计决策:一个基于UCON的协作网格系统,另一个基于ZBAC的基于SOA的系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号