首页> 外文期刊>Journal of Universal Computer Science >A New Hybrid Access Control Model for Security Policies in Multimodal Applications Environments
【24h】

A New Hybrid Access Control Model for Security Policies in Multimodal Applications Environments

机译:多模式应用程序环境中安全策略的新混合访问控制模型

获取原文
           

摘要

New technologies as cloud computing and internet of things (IoT) has expanded the range of multimodal applications. This expansion, in several computing and heterogeneous environments, makes access control an important issue in multimodal applications. Indeed, a variety of access control models have been developed to address different aspects of security problems. The two most popular basic models are: Role Based Access Control (RBAC) and Attribute Based Access Control (ABAC). The both models RBAC and ABAC have their specific features and they can complement each other. For that, providing a hybrid model which considers both concepts "roles" as well as "attributes" has become an important research topic. This paper proposes a new access control model based principally on roles, attributes, access modes and the type of resources. An empirical method is applied to compare the new proposed model versus three existing models: RBAC, ABAC, and the hybrid model Attribute Enhanced RBAC (AERBAC). The results of the empirical method demonstrate that the new proposed model acquires the advantages of the two models RBAC and ABAC and avoids their limitations. In fact, the new proposed model reduces the complexity of security policies and allows expressing the fine granularity of systems without any explosion in the number of roles or rules in the security policy.
机译:云计算和物联网(IoT)等新技术扩大了多模式应用程序的范围。在多种计算和异构环境中的这种扩展使访问控制成为多模式应用程序中的重要问题。实际上,已经开发出各种访问控制模型来解决安全问题的不同方面。两种最受欢迎​​的基本模型是:基于角色的访问控制(RBAC)和基于属性的访问控制(ABAC)。 RBAC和ABAC两种模型都有其特定的功能,并且可以相互补充。为此,提供一种既考虑“角色”又考虑“属性”的混合模型已经成为重要的研究课题。本文提出了一种新的访问控制模型,主要基于角色,属性,访问模式和资源类型。应用经验方法将新提议的模型与三个现有模型进行比较:RBAC,ABAC和混合模型属性增强RBAC(AERBAC)。经验方法的结果表明,新提出的模型获得了RBAC和ABAC两个模型的优点,并避免了它们的局限性。实际上,新提出的模型降低了安全策略的复杂性,并允许表达系统的精细粒度,而安全策略中的角色或规则数量没有任何爆炸式增长。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号