...
首页> 外文期刊>International Journal of Information Security >Concrete- and abstract-based access control
【24h】

Concrete- and abstract-based access control

机译:基于具体和抽象的访问控制

获取原文
获取原文并翻译 | 示例

摘要

Access control models allow expressing access control rules (also called policies) stating that certain subjects (or users) have or do not have the right (or privilege) to access certain objects in order to execute certain actions under certain conditions. Several existing models allow expressing rules only for specific subjects, objects and actions. Role-based access control (RBAC) introduced the notion of role, which is an abstraction over subjects. Organization-based access control (OrBAC) generalized further, by allowing specifying rules involving abstract subjects, abstract actions and abstract objects. We propose here a model that allows expressing rules involving any combinations of abstract or concrete subjects, actions and objects, as well as conditions over them. For this reason, our model is called concrete- and abstract-based access control model (CABAC). The semantics of our model is expressed in terms of first order predicate logic. Temporal, spatial, knowledge and historical contexts can be specified and combined. We show how in this model it is possible to express hierarchies of subjects, objects and actions as well as propagation of policies over hierarchies. Further, while in most models subjects, objects and actions, whether concrete or abstract, must be specified statically, it is possible in our model to specify subjects, actions and objects dynamically, i.e., according to conditions that can vary over time. Access control rules can also be explicitly revoked and subjected to different types of constraints, among which are cardinality constraints and separation of duties.
机译:访问控制模型允许表达访问控制规则(也称为策略),表明某些主题(或用户)具有或不具有访问某些对象的权限(或特权),以便在某些条件下执行某些动作。现有的几种模型仅允许表达特定主题,对象和动作的规则。基于角色的访问控制(RBAC)引入了角色概念,它是对主题的抽象。通过允许指定涉及抽象主题,抽象动作和抽象对象的规则,可以进一步概括基于组织的访问控制(OrBAC)。我们在这里提出一个模型,该模型允许表达涉及抽象或具体主题,动作和对象以及它们的条件的任何组合的规则。因此,我们的模型称为基于具体和抽象的访问控制模型(CABAC)。我们模型的语义是用一阶谓词逻辑表示的。可以指定和组合时间,空间,知识和历史背景。我们展示了如何在此模型中表达主题,对象和动作的层次结构以及策略在层次结构上的传播。此外,尽管在大多数模型中必须静态指定主题,对象和动作,无论是具体的还是抽象的,但在我们的模型中可以动态指定主题,动作和对象,即根据随时间变化的条件。访问控制规则也可以显式撤销,并受到不同类型的约束,其中包括基数约束和职责分离。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号