...
首页> 外文期刊>IBM Systems Journal >Abstract interdomain security assertions: A basis for extra-grid virtual organizations
【24h】

Abstract interdomain security assertions: A basis for extra-grid virtual organizations

机译:抽象的域间安全性断言:超网格虚拟组织的基础

获取原文
           

摘要

One significant challenge in building grids between organizations with heterogeneous security systems is the need to express and enforce security policies that specify the users in one organization (the source domain) who are allowed to access the resources in another organization (the target domain). This requires linking the syntax and semantics of security assertions referring to users and their attributes in the source domain to those referring to resources in the target domain. This paper suggests some basic requirements for solving this problem, in particular, an abstract form of interdomain security assertion (IDSA) relying, for instance, on globally meaningful URIs (Uniform Resource Identifiers) to refer to users, resources, and their attributes. This canonical abstract form of IDSA is, however, used strictly for assertion mapping purposes. It may—but need not—be visible in any concrete security assertion syntax in any domain. The paper further suggests different scenarios in which URIs for users, resources, and attributes defined in one domain can be mapped to semantically meaningful references—with varying degrees of granularity and accountability—in another domain where they would otherwise be meaningless.
机译:在具有异构安全系统的组织之间建立网格的一个重大挑战是需要表达和实施安全策略,这些策略指定一个组织(源域)中的用户,这些用户可以访问另一组织(目标域)中的资源。这要求将引用源域中的用户及其属性的安全性断言的语法和语义链接到引用目标域中的资源的安全性断言的语法和语义。本文提出了解决此问题的一些基本要求,特别是域间安全声明(IDSA)的抽象形式,例如,它依赖于全局有意义的URI(统一资源标识符)来引用用户,资源及其属性。但是,IDSA的这种规范的抽象形式严格用于声明映射。在任何域的任何具体安全性声明语法中,它可能(但不一定)可见。本文还提出了不同的方案,其中可以将在一个域中定义的用户,资源和属性的URI映射到语义上有意义的引用(具有不同程度的粒度和责任制),而在其他情况下它们将毫无意义。

著录项

  • 来源
    《IBM Systems Journal》 |2004年第4期|P.689-701|共13页
  • 作者

  • 作者单位
  • 收录信息
  • 原文格式 PDF
  • 正文语种
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号