首页> 外文期刊>IEEE Transactions on Knowledge and Data Engineering >Analyzing and Managing Role-Based Access Control Policies
【24h】

Analyzing and Managing Role-Based Access Control Policies

机译:分析和管理基于角色的访问控制策略

获取原文
获取原文并翻译 | 示例

摘要

Today more and more security-relevant data is stored on computer systems; security-critical business processes are mapped to their digital counterparts. This situation applies to various domains such as health care industry, digital government, and financial service institutes requiring that different security requirements must be fulfilled. Authorisation constraints can help the policy architect design and express higher-level organisational rules. Although the importance of authorisation constraints has been addressed in the literature, there does not exist a systematic way to verify and validate authorisation constraints. In this paper, we specify both non-temporal and history-based authorisation constraints in the Object Constraint Language (OCL) and first-order linear temporal logic (LTL). Based upon these specifications, we attempt to formally verify role-based access control policies with the help of a theorem prover and to validate policies with the USE system, a validation tool for OCL constraints. We also describe an authorisation engine, which supports the enforcement of authorisation constraints.
机译:如今,越来越多与安全性相关的数据存储在计算机系统中。对安全性至关重要的业务流程已映射到其数字副本。这种情况适用于各个领域,例如医疗保健行业,数字政府和金融服务机构,要求必须满足不同的安全要求。授权约束可以帮助策略架构师设计和表达更高级别的组织规则。尽管授权约束的重要性已在文献中得到了解决,但尚不存在验证和验证授权约束的系统方法。在本文中,我们在对象约束语言(OCL)和一阶线性时态逻辑(LTL)中指定了非时间和基于历史的授权约束。基于这些规范,我们尝试在定理证明者的帮助下正式验证基于角色的访问控制策略,并使用USE系统(OCL约束的验证工具)来验证策略。我们还描述了一个授权引擎,它支持授权约束的实施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号