首页> 外文期刊>Journal of computer security >Distributed credential chain discovery in trust management
【24h】

Distributed credential chain discovery in trust management

机译:信任管理中的分布式证书链发现

获取原文

摘要

We introduce a simple Role-based Trust-management language RT_0 and a set-theoretic semantics for it. We also introduce credential graphs as a searchable representation of credentials in RT_0 and prove that reachability in credential graphs is sound and complete with respect to the semantics of RT_0. Based on credential graphs, we give goal-directed algorithms to do credential chain discovery in RT_0, both when credential storage is centralized and when credential storage is distributed. A goal-directed algorithm begins with an access-control query and searches for credentials relevant to the query, while avoiding considering the potentially very large number of credentials that are unrelated to the access-control decision at hand. This approach provides better expected-case performance than bottom-up algorithms. We show how our algorithms can be applied to SDSI 2.0 (the 'SDSI' part of SPKI/SDSI 2.0). Our goal-directed, distributed chain discovery algorithm finds and retrieves credentials as needed. We prove that the algorithm is correct by proving that the algorithm is sound and complete with respect to the credential graph composed of the credentials it retrieves, and that the algorithm retrieves all credentials that constitute a traversable chain. We further introduce a storage type system for RT_0, which guarantees traversability of chains when credentials are well typed. This type system can also help improve search efficiency by guiding search in the right direction, making distributed chain discovery with large number of credentials feasible.
机译:我们介绍了一种简单的基于角色的信任管理语言RT_0,并为其提供了一种集理论的语义。我们还引入了凭证图作为RT_0中凭证的可搜索表示,并证明了凭证图中的可到达性相对于RT_0的语义而言是健全且完整的。基于凭证图,我们给出了目标导向算法来在RT_0集中存储凭证和分配凭证存储时在RT_0中进行凭证链发现。目标导向算法从访问控制查询开始,并搜索与查询相关的凭据,同时避免考虑可能的大量凭据,这些凭据与当前的访问控制决策无关。与自底向上算法相比,这种方法提供了更好的预期案例性能。我们展示了如何将算法应用于SDSI 2.0(SPKI / SDSI 2.0的“ SDSI”部分)。我们的目标导向的分布式链发现算法可根据需要查找和检索凭证。我们通过证明算法相对于由其检索到的凭证组成的凭证图是合理且完整的,并且算法会检索出构成可遍历链的所有凭证,来证明该算法是正确的。我们还为RT_0引入了一种存储类型系统,该系统可在正确键入凭据时保证链的可遍历性。这种类型的系统还可以通过在正确的方向上引导搜索来帮助提高搜索效率,从而使具有大量凭证的分布式链发现成为可能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号