...
首页> 外文期刊>Requirements Engineering >Conviviality-driven access control policy
【24h】

Conviviality-driven access control policy

机译:欢乐驱动的访问控制策略

获取原文
获取原文并翻译 | 示例

摘要

Nowadays many organizations experience security incidents due to unauthorized access to information. To reduce the risk of such incidents, security policies are often employed to regulate access to information. Such policies, however, are often too restrictive, and users do not have the rights necessary to perform assigned duties. As a consequence, access control mechanisms are perceived by users as a barrier and thus bypassed, making the system insecure. In this paper, we draw a bridge between the social concept of conviviality and access control. Conviviality has been introduced as a social science concept for ambient intelligence and multi-agent systems to highlight soft qualitative requirements like user-friendliness of systems. To bridge the gap between conviviality and security, we propose a methodological framework for updating and adapting access control policies based on conviviality recommendations. Our methodology integrates and extends existing techniques to assist system designers in the derivation of access control policies from socio-technical requirements of the system, while taking into account the conviviality of the system. We illustrate our framework using the Ambient Assisted Living use case from the HotCity of Luxembourg.
机译:如今,许多组织由于未经授权访问信息而遇到安全事件。为了降低此类事件的风险,通常采用安全策略来规范对信息的访问。但是,此类策略通常过于严格,用户没有执行分配的职责所必需的权限。结果,访问控制机制被用户视为障碍,因此被绕开,使系统不安全。在本文中,我们在欢乐的社会概念和访问控制之间架起了一座桥梁。欢乐已被引入作为环境情报和多主体系统的社会科学概念,以突出软质的要求,例如系统的用户友好性。为了弥合欢乐与安全之间的鸿沟,我们提出了一种基于欢乐建议来更新和调整访问控制策略的方法框架。我们的方法论整合并扩展了现有技术,以帮助系统设计人员从系统的社会技术要求中推导访问控制策略,同时考虑到系统的便利性。我们使用来自卢森堡HotCity的Ambient Assisted Living用例来说明我们的框架。

著录项

  • 来源
    《Requirements Engineering 》 |2015年第4期| 363-382| 共20页
  • 作者单位

    Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust SnT, Lab Adv Software SYst LASSY, Luxembourg, Luxembourg;

    Eindhoven Univ Technol, Dept Math & Comp Sci, Secur Grp, NL-5600 MB Eindhoven, Netherlands;

    Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust SnT, Luxembourg, Luxembourg;

    Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust SnT, Luxembourg, Luxembourg;

    Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust SnT, Luxembourg, Luxembourg;

    Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust SnT, Luxembourg, Luxembourg;

    Univ Luxembourg, Interdisciplinary Ctr Secur Reliabil & Trust SnT, Lab Adv Software SYst LASSY, Luxembourg, Luxembourg;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Convivilaity; Access control; Negotiable and non-negotiable authorizations; Requirement model;

    机译:保密性;访问控制;可协商和不可协商的授权;需求模型;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号