首页> 外文期刊>Computers & Security >A framework of composable access control features: Preserving separation of access control concerns from models to code
【24h】

A framework of composable access control features: Preserving separation of access control concerns from models to code

机译:可组合访问控制功能的框架:保持访问控制关注点从模型到代码的分离

获取原文
获取原文并翻译 | 示例
       

摘要

Modeling of security policies, along with their realization in code, must be an integral part of the software development process, to achieve an acceptable level of security for a software application. Among all of the security concerns (e.g. authentication, auditing, access control, confidentiality, etc.), this paper addresses the incorporation of access control into software. The approach is to separate access control concerns from the rest of the design. To assist designers to visualize access control policies separated from non-security concerns, this paper proposes a set of access control diagrams, I.e., extensions to the UML to represent three main access control models: role-based access control (RBAC), mandatory access control (MAC), and discretionary access control (DAC). To better adapt to changing requirements, and assist designers to customize access control policies, this paper proposes a set of access control features, I.e., small components that realize specific capabilities of access control models. Designers can select the features they require, and compose them to yield different access control policies. When transitioning into code, the main focus is to preserve separation of access control concerns. This paper describes an approach to realize access control diagrams and features in code through structure-preserving mappings, describes three different approaches to enforce access control in code, and evaluates the way each of them separate access control from other concerns.
机译:安全策略的建模及其在代码中的实现,必须是软件开发过程中不可或缺的一部分,以实现软件应用程序可接受的安全级别。在所有安全问题(例如身份验证,审计,访问控制,机密性等)中,本文致力于将访问控制合并到软件中。该方法是将访问控制问题与设计的其余部分分开。为了帮助设计人员可视化与非安全问题分开的访问控制策略,本文提出了一组访问控制图,即UML的扩展,以表示三种主要访问控制模型:基于角色的访问控制(RBAC),强制访问控制(MAC)和任意访问控制(DAC)。为了更好地适应不断变化的需求并帮助设计人员自定义访问控制策略,本文提出了一组访问控制功能,即实现访问控制模型特定功能的小型组件。设计人员可以选择所需的功能,并对其进行组合以产生不同的访问控制策略。过渡到代码时,主要重点是保持访问控制关注点的分离。本文介绍了一种通过保留结构的映射在代码中实现访问控制图和功能的方法,描述了三种在代码中强制执行访问控制的方法,并评估了每种方法将访问控制与其他问题分开的方式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号