...
首页> 外文期刊>Journal of computer security >A theory for comparing the expressive power of access control models
【24h】

A theory for comparing the expressive power of access control models

机译:比较访问控制模型的表达能力的理论

获取原文
获取原文并翻译 | 示例
           

摘要

We present a theory for comparing the expressive power of access control models. The theory is based on simulations that preserve security properties. We perceive access control systems as state-transition systems and present two kinds of simulations, reductions and state-matching reductions. In applying the theory, we highlight four new results and discuss these results in the context of other results that can be inferred or are known. One result indicates that the access matrix scheme due to Harrison, Ruzzo and Ullman is limited in its expressive power when compared with a trust-management scheme, thereby formally establishing a conjecture from the literature. A second result is that a particular RBAC (Role-Based Access Control) scheme, ARBAC97, may be limited in its expressive power, thereby countering claims in the literature that RBAC is more expressive than DAC (Discretionary Access Control). A third result demonstrates that the ability to check for the absence of rights (in addition to the presence of rights) can cause a scheme to be more expressive. A fourth result is that a trust-management scheme is at least as expressive as RBAC with a particular administrative scheme (the URA97 component of ARBAC97).
机译:我们提出了一种用于比较访问控制模型的表达能力的理论。该理论基于保留安全属性的模拟。我们将访问控制系统视为状态转换系统,并给出两种模拟,简化和状态匹配简化。在应用该理论时,我们重点介绍了四个新结果,并在可以推断或已知的其他结果的背景下讨论了这些结果。一个结果表明,与信任管理方案相比,归因于Harrison,Ruzzo和Ullman的访问矩阵方案在表达能力上受到限制,从而正式地从文献中建立了一个猜想。第二个结果是,特定的RBAC(基于角色的访问控制)方案ARBAC97的表达能力可能受到限制,从而与文献中的说法相反,即RBAC比DAC(自由访问控制)更具表达能力。第三个结果表明,检查权利是否存在(除了权利存在之外)的能力可以使方案更具表现力。第四个结果是,信任管理方案与特定管理方案(ARBAC97的URA97组件)的表达至少与RBAC一样。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号