首页> 外文期刊>IEEE transactions on dependable and secure computing >A Provenance-Aware Access Control Framework with Typed Provenance
【24h】

A Provenance-Aware Access Control Framework with Typed Provenance

机译:具有类型出处的出处感知访问控制框架

获取原文
获取原文并翻译 | 示例

摘要

Provenance is a directed graph that captures historical information about data items in Provenance-Aware Systems (PAS). A variety of access control models and policy languages specific to PAS have been recently discussed in literature. However, it is still not clear how to efficiently specify provenance-aware access control policies and how to effectively enforce these policies with respect to complex provenance graph that can only be captured at run-time. To this end, we design and implement a provenance-aware access control framework with a layered architecture that features an abstract layer, including a Typed Provenance Model (TPM) and a set of TPM interpreters. TPM includes a set of abstract provenance types enabling efficient specification of provenance-aware policies. New provenance types can be composed of extant ones for specifying new policies. TPM interpreters can be integrated to enable the policy enforcement with respect to provenance graphs in different physical representations. By treating provenance types as special attributes, the proposed framework enables an adoption of provenance-aware access control in existing attribute-based access control frameworks, such as XACML-compliant ones. We implement the proposed framework by extending SUN's XACML implementation and show that it facilitates the specification of provenance-aware policies in XACML with minor extensions. We also analyze the performance of the proposed framework.
机译:来源是一个有向图,可捕获有关来源感知系统(PAS)中数据项的历史信息。最近在文献中讨论了各种特定于PAS的访问控制模型和策略语言。但是,仍不清楚如何有效地指定可识别出处的访问控制策略,以及如何针对只能在运行时捕获的复杂出处图有效地实施这些策略。为此,我们设计并实现了一个具有分层架构的可识别出处的访问控制框架,该分层结构具有一个抽象层,其中包括类型化出处模型(TPM)和一组TPM解释器。 TPM包括一组抽象出处类型,可以有效地指定出处感知策略。新的来源类型可以由用于指定新策略的现有类型组成。可以集成TPM解释器,以针对不同物理表示形式的源图执行策略。通过将出处类型视为特殊属性,提出的框架可以在基于XACML的现有基于属性的访问控制框架中采用出处感知的访问控制。我们通过扩展SUN的XACML实现来实现所提出的框架,并显示该框架通过少量扩展有助于在XACML中规范出处感知策略。我们还分析了建议框架的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号