...
首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Privacy-Preserving Enforcement of Spatially Aware RBAC
【24h】

Privacy-Preserving Enforcement of Spatially Aware RBAC

机译:空间感知RBAC的隐私保护执行

获取原文
获取原文并翻译 | 示例
           

摘要

Several models for incorporating spatial constraints into role-based access control (RBAC) have been proposed, and researchers are now focusing on the challenge of ensuring such policies are enforced correctly. However, existing approaches have a major shortcoming, as they assume the server is trustworthy and require complete disclosure of sensitive location information by the user. In this work, we propose a novel framework and a set of protocols to solve this problem. Specifically, in our scheme, a user provides a service provider with role and location tokens along with a request. The service provider consults with a role authority and a location authority to verify the tokens and evaluate the policy. However, none of the servers learn the requesting user's identity, role, or location. In this paper, we define the protocols and the policy enforcement scheme, and present a formal proof of a number of security properties.
机译:已经提出了几种用于将空间约束纳入基于角色的访问控制(RBAC)的模型,并且研究人员现在正在关注确保正确执行此类策略的挑战。但是,现有方法存在主要缺点,因为它们假定服务器是可信赖的,并且要求用户完全公开敏感位置信息。在这项工作中,我们提出了一个新颖的框架和一套协议来解决这个问题。具体来说,在我们的方案中,用户向服务提供商提供角色和位置令牌以及请求。服务提供商咨询角色授权和位置授权以验证令牌并评估策略。但是,没有一台服务器了解请求用户的身份,角色或位置。在本文中,我们定义了协议和策略实施方案,并给出了许多安全属性的形式证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号