首页> 外文期刊>Journal of computer security >Constraint based role based access control in the SECTET-framework
【24h】

Constraint based role based access control in the SECTET-framework

机译:在SECRET框架中基于约束的基于角色的访问控制

获取原文
获取原文并翻译 | 示例
           

摘要

With respect to Service Oriented Architectures (SOA's) paradigm, the core Role Based Access Control (RBAC) has several limitations. In SOA, permissions to execute web services are not assigned statically to roles but are associated with a set of Permission Assignment Constraints (PAC) upon the fulfilment of which a role is assigned a permission to execute a web service. Further, the RBAC does not support partial inheritance which is an integral requirement in SOA. A major challenge in SOA is the inheritance of permissions associated with PAC in the presence of role hierarchies. This contribution has three objectives. First we propose an extension to Role Based Aecess Control (available at csrc.nist.gov/rbac/), which we call Constraint based RBAC (CRBAC), in order to make RBAC applicable to the dynamic environment of SOA. Within CRBAC, a high-level language - called SECTET-PL (available at http:// qe-informatik.uibk.ac.at/~muhammad/TechnicalReportSECTETPL.pdf) is used for the specification of PAC. Being part of the SECTET-framework for model-driven security for B2B-workflows, SECTET-PL is a policy language influenced by OCL (available at http://www.omg.org/docs/ptc/03-10-14.pdf) and interpreted in the context of UML models. Using the Model Driven Architecture (MDA) (available at http://www.omg.org/mda) paradigm, we then describe the transformation of high-level security models to low-level web services standard artefacts with the help of the Eclipse Modelling Framework and OpenArchitectureWare. Finally, we present the target architecture of the SECTET-framework used to realize the security artefacts generated from the transformations and thus completes the cycle of MDA.
机译:关于面向服务的体系结构(SOA)范例,基于角色的核心访问控制(RBAC)具有多个限制。在SOA中,执行Web服务的权限不是静态地分配给角色,而是与一组权限分配约束(PAC)相关联,在该权限分配约束完成后,将向角色分配执行Web服务的权限。此外,RBAC不支持部分继承,这是SOA中不可或缺的要求。 SOA中的主要挑战是在角色层次结构存在的情况下继承与PAC相关的权限。该贡献具有三个目标。首先,我们建议对基于角色的访问控制进行扩展(可在csrc.nist.gov/rbac/上获得),我们将其称为基于约束的RBAC(CRBAC),以使RBAC适用于SOA的动态环境。在CRBAC中,称为SECTET-PL的高级语言(可从http://qe-informatik.uibk.ac.at/~muhammad/TechnicalReportSECTETPL.pdf获得)用于PAC规范。作为用于B2B工作流的模型驱动安全性的SECTET框架的一部分,SECTET-PL是一种受OCL影响的策略语言(可从http://www.omg.org/docs/ptc/03-10-14获得)。 pdf),并在UML模型的上下文中进行解释。然后,使用模型驱动的体系结构(MDA)(可从http://www.omg.org/mda获得)范式,描述在Eclipse的帮助下将高级安全模型转换为低级Web服务标准工件的方法。建模框架和OpenArchitectureWare。最后,我们介绍了SECTET框架的目标体系结构,该框架用于实现从转换生成的安全工件,从而完成MDA的循环。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号