...
【24h】

Object-Specific Role-Based Access Control

机译:对象的基于角色的访问控制

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The proper management of privacy and security constraints in information systems in general and access control in particular constitutes a tremendous, but still prevalent challenge. Role-based access control (RBAC) and its variations can be considered as the widely adopted approach to realize authorization in information systems. However, RBAC lacks a proper object-specific support, which disallows establishing the fine-grained access control required in many domains. By comparison, attribute-based access control (ABAC) enables a fine-grained access control based on policies and rules evaluating attributes. As a drawback, ABAC lacks the abstraction of roles. Moreover. it is challenging to engineer and to audit the granted privileges encoded in rule-based policies. This paper presents the generic approach of object-specific role-based access control (ORAC). On one hand, ORAC enables information system engineers, administrators and users to utilize the well-known principle of roles. On the other hand, ORAC allows realizing the access to objects in a fine-grained way where required. The approach was systematically established according to well-elicited key requirements for fine-grained access control in information systems. For the purpose of evaluation, the approach was applied to real-world scenarios and implemented in a proof-of-concept prototype demonstrating its feasibility and applicability.
机译:尤其构成了一般和访问控制的信息系统中隐私和安全限制的适当管理,尤其构成了巨大但仍然普遍的挑战。基于角色的访问控制(RBAC)及其变化可以被认为是广泛采用的信息系统中实现授权的方法。然而,RBAC缺乏适当的对象支持,该支持不允许建立许多域中所需的细粒度访问控制。相比之下,基于属性的访问控制(ABAC)可以基于策略和规则评估属性的细粒度访问控制。作为一个缺点,ABAC缺乏角色的抽象。而且。它对工程师有挑战性,并审核基于规则的策略编码的授权权限。本文介绍了基于对象的基于角色的访问控制(ORAC)的通用方法。一方面,ORAC使信息系统工程师,管理员和用户能够利用众所周知的角色原则。另一方面,ORAC允许以所需的方式以精细的方式实现对物体的访问。根据信息系统中细粒度访问控制的良好引发的关键要求,系统地建立了这种方法。为评估目的,该方法应用于真实世界的情景,并在概念验证原型中实施,证明了其可行性和适用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号