首页> 外文期刊>Computers & Security >Fine-grained integration of access control policies
【24h】

Fine-grained integration of access control policies

机译:访问控制策略的细粒度集成

获取原文
获取原文并翻译 | 示例
           

摘要

Collaborative and distributed applications, such as dynamic coalitions and virtualized grid computing, often require integrating access control policies of collaborating parties. Such an integration must be able to support complex authorization specifications and the finegrained integration requirements that the various parties may have. In this paper, we introduce an algebra for fine-grained integration of sophisticated policies. The algebra, which consists of three binary and two unary operations, is able to support the specification of a large variety of integration constraints. For ease of use, we also introduce a set of derived operators and provide guidelines for users to edit a policy with desired properties. To assess the expressive power of our algebra, we define notion of completeness and prove that our algebra is complete and minimal with respect to the notion. We then propose a framework that uses the algebra for the fine-grained integration of policies expressed in XACML. We also present a methodology for generating the actual integrated XACML policy, based on the notion of Multi-Terminal Binary Decision Diagrams. Experimental results have demonstrated both effectiveness and efficiency of our approach. In addition, we also discuss issues regarding obligations.
机译:诸如动​​态联盟和虚拟化网格计算之类的协作和分布式应用程序通常需要集成协作方的访问控制策略。这种集成必须能够支持复杂的授权规范以及各方可能具有的细粒度集成要求。在本文中,我们介绍了用于精细集成精细策略的代数。由三个二进制和两个一元运算组成的代数能够支持各种集成约束的规范。为了易于使用,我们还引入了一组派生运算符,并为用户提供了编辑具有所需属性的策略的准则。为了评估代数的表达能力,我们定义了完整性的概念,并证明了我们的代数是完整的并且相对于该概念而言是最小的。然后,我们提出一个框架,该框架将代数用于XACML中表达的策略的细粒度集成。我们还基于多终端二进制决策图的概念,提出了一种用于生成实际的集成XACML策略的方法。实验结果证明了我们方法的有效性和效率。此外,我们还将讨论有关义务的问题。

著录项

  • 来源
    《Computers & Security》 |2011年第3期|p.91-107|共17页
  • 作者单位

    Department of Computer Science, Purdue University, 305 N. University St, West Lafayette, USA;

    Department of Computer Science, Missouri University of Science and Technology, USA;

    Department of Computer Science, Purdue University, 305 N. University St, West Lafayette, USA;

    Department of Computer Science, Purdue University, 305 N. University St, West Lafayette, USA;

    IBM TJ. Watson Research Center, USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    access control; algebra; framework; policy integration; XACML;

    机译:访问控制;代数框架政策整合;XACML;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号