...
首页> 外文期刊>Journal of computer security >A logical framework for history-based access control and reputation systems
【24h】

A logical framework for history-based access control and reputation systems

机译:基于历史的访问控制和信誉系统的逻辑框架

获取原文
获取原文并翻译 | 示例
           

摘要

Reputation systems are meta systems that record, aggregate and distribute information about principals' behaviour in distributed applications. Similarly, history-based access control systems make decisions based on programs' past security-sensitive actions. While the applications are distinct, the two types of systems are fundamentally making decisions based on information about the past behaviour of an entity. A logical policy-centric framework for such behaviour-based decision-making is presented. In the framework, principals specify policies which state precise requirements on the past behaviour of other principals that must be fulfilled in order for interaction to take place. The framework consists of a formal model of behaviour, based on event structures; a declarative logical language for specifying properties of past behaviour; and efficient dynamic algorithms for checking whether a particular behaviour satisfies a property from the language. It is shown how the framework can be extended in several ways, most notably to encompass parameterized events and quantification over parameters. In an extended application, it is illustrated how the framework can be applied for dynamic history-based access control for safe execution of unknown and untrusted programs.
机译:信誉系统是在分布式应用程序中记录,汇总和分发有关委托人行为的信息的元系统。同样,基于历史的访问控制系统会根据程序过去对安全敏感的操作来做出决策。尽管应用程序是不同的,但两种类型的系统从根本上是基于有关实体过去行为的信息来进行决策的。提出了基于逻辑的以政策为中心的框架,用于这种基于行为的决策。在框架中,委托人指定了策略,这些策略阐明了对其他委托人的过去行为的精确要求,必须进行这些交互才能进行交互。该框架由基于事件结构的正式行为模型组成;一种声明性逻辑语言,用于指定过去行为的属性;高效的动态算法,用于检查特定行为是否满足该语言的属性。它显示了如何以几种方式扩展框架,最值得注意的是涵盖了参数化事件和参数量化。在扩展的应用程序中,说明了如何将框架应用于基于动态历史记录的访问控制,以安全执行未知和不受信任的程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号