...
首页> 外文期刊>International Journal of Information Security >Adding support to XACML for multi-domain user to user dynamic delegation of authority
【24h】

Adding support to XACML for multi-domain user to user dynamic delegation of authority

机译:向XACML添加对多域用户到用户动态授权的支持

获取原文
获取原文并翻译 | 示例

摘要

We describe adding support for dynamic delegation of authority (DOA) between users in multiple administrative domains, to the XACML model for authorisa_tion decision making. DOA is enacted via the issuing of cre_dentials from one user to another, and follows the role based access control model. We present the problems and require_ments that such a delegation model demands, the policy ele_ments that are necessary to control the delegation chains and a description of the architected solution. We propose a new conceptual entity called the credential validation service (CVS) to work alongside the XACML PDP. We describe our implementation of the CVS and present performance mea_surements for validating delegated chains of credentials.
机译:我们描述了在XACML模型中添加对多个管理域中用户之间动态授权(DOA)的支持,以进行授权决策。 DOA是通过从一个用户向另一个用户颁发凭据来制定的,并且遵循基于角色的访问控制模型。我们提出了这种委托模型所要求的问题和要求,控制委托链所必需的策略要素以及对架构解决方案的描述。我们提出了一个新的概念实体,称为凭证验证服务(CVS),可以与XACML PDP一起使用。我们描述了CVS的实现,并介绍了用于验证委托的凭证链的性能mea_surements。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号