首页> 外文期刊>International journal of computer science and network security >Design and Evaluation of Policy Based Authorization Model for large scale Distributed Systems
【24h】

Design and Evaluation of Policy Based Authorization Model for large scale Distributed Systems

机译:基于策略的大型分布式系统授权模型的设计与评估

获取原文
获取原文并翻译 | 示例

摘要

Large scale distributed systems enable sharing of resources and services scattered over geographically dispersed, heterogeneous, autonomous administrative domains. Two main entities interacting with each other over a distributed system are service requesters and service providers. The service requesters belonging to a particular administrative domain may request access to resources/services available over same or other administrative domains. Similarly a service provider belonging to a particular administrative domain may expose its resources/services over same or other administrative domains. The service requesters belonging to one administrative domain ? generally have different access rights in different administrative domains. Determining what a service requester is authorized to do in the same or other administrative domains is a difficult task. The overall authorization and access control becomes more complex when service providers attach authorization and access control related policies with their resources/services and provide access to those resources/services based on conformance to established policies. These policies may include authentication, privacy, trust, network workload, business and management etc. related aspects of authorization and access control. Designing an authorization and access control system for such an environment is a complex task and introduces many challenging technology and management related issues. In this paper we have made an attempt to define and implement a policy based authorization and access control framework that can be used to determine the access rights of a subject in different administrative domains and supports policy-based access to resources/services scattered over a distributed system. The framework proposed is scalable, flexible and has been implemented through web services. The paper also discusses prototype implementation of the proposed framework.
机译:大型分布式系统可以共享分散在地理位置分散,异构,自治的管理域中的资源和服务。通过分布式系统相互交互的两个主要实体是服务请求者和服务提供者。属于特定管理域的服务请求者可以请求访问在相同或其他管理域上可用的资源/服务。类似地,属于特定管理域的服务提供商可以在相同或其他管理域上公开其资源/服务。属于一个管理域的服务请求者?通常在不同的管理域中具有不同的访问权限。确定授权服务请求者在相同或其他管理域中执行的操作是一项艰巨的任务。当服务提供商将与授权和访问控制相关的策略与其资源/服务一起附加,并基于对已建立策略的一致性来提供对那些资源/服务的访问时,总体授权和访问控制将变得更加复杂。这些策略可以包括认证,隐私,信任,网络工作量,业务和管理等与授权和访问控制有关的方面。为这种环境设计授权和访问控制系统是一项复杂的任务,并引入了许多具有挑战性的技术和管理相关问题。在本文中,我们尝试定义和实现基于策略的授权和访问控制框架,该框架可用于确定主题在不同管理域中的访问权限,并支持对分散在分布式系统中的资源/服务进行基于策略的访问系统。所提出的框架是可扩展的,灵活的,并已通过Web服务实现。本文还讨论了所提出框架的原型实现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号