...
首页> 外文期刊>IEEE transactions on dependable and secure computing >The Authorization Policy Existence Problem
【24h】

The Authorization Policy Existence Problem

机译:授权策略存在问题

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Constraints such as separation-of-duty are widely used to specify requirements that supplement basic authorization policies. However, the existence of constraints (and authorization policies) may mean that a user is unable to fulfill her/his organizational duties because access to resources has been denied. In short, there is a tension between the need to protect resources (using policies and constraints) and the availability of resources. Recent work on workflow satisfiability and resiliency in access control asks whether this tension compromises the ability of an organization to achieve its objectives. In this paper, we develop a new method of specifying constraints which subsumes much related work and allows a wider range of constraints to be specified. The use of such constraints leads naturally to a range of questions related to "policy existence", where a positive answer means that an organization's objectives can be realized. We analyze the complexity of these policy existence questions and, for particular sub-classes of constraints defined by our language, develop fixed-parameter tractable algorithms to solve them.(1) 1. An extended abstract of this paper appeared in the Proceedings of the Seventh ACM Conference on Data and Application Security and Privacy [1]. Research was partially supported by Leverhulme Trust grant RPG-2018-161 and Royal Society Wolfson Research Merit Award.
机译:诸如占空比分离的约束被广泛用于指定补充基本授权策略的要求。但是,限制(和授权策略)的存在可能意味着用户无法满足她/他的组织职责,因为否认了资源的访问。简而言之,需要保护资源(使用策略和约束)和资源可用性之间的紧张关系。访问控制中的工作流程可满足性和弹性的最新工作询问此紧张是否会损害组织实现其目标的能力。在本文中,我们开发了一种指定约束的新方法,该制约件向上载有许多相关的工作,并允许指定更广泛的约束。这种约束的使用自然导致了与“政策存在”有关的一系列问题,其中肯定答案意味着可以实现组织的目标。我们分析了这些策略存在问题的复杂性,以及我们语言定义的特定约束的特定子类,开发固定参数的易解算法以解决它们。(1)1。本文的扩展摘要出现在课程中第七次ACM数据和应用程序安全和隐私[1]。 Reverhulme Trust RPG-2018-161和Royal Society Wolfson Research Merit Award部分支持研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号