...
首页> 外文期刊>International Journal of Information Security >EXAM: A comprehensive environment for the analysis of access control policies
【24h】

EXAM: A comprehensive environment for the analysis of access control policies

机译:考试:用于分析访问控制策略的综合环境

获取原文
获取原文并翻译 | 示例

摘要

Policy integration and inter-operation is often a crucial requirement when parties with different access control policies need to participate in collaborative applications and coalitions. Such requirement is even more difficult to address for dynamic large-scale collaborations, in which the number of access control policies to analyze and compare can be quite large. An important step in policy integration and inter-operation is to analyze the similarity of policies. Policy similarity can sometimes also be a pre-condition for establishing a collaboration, in that a party may enter a collaboration with another party only if the policies enforced by the other party match or are very close to its own policies. Existing approaches to the problem of analyzing and comparing access control policies are very limited, in that they only deal with some special cases. By recognizing that a suitable approach to the policy analysis and comparison requires combining different approaches, we propose in this paper a comprehensive environment-EXAM. The environment supports various types of analysis query, which we categorize in the paper. A key component of such environment, on which we focus in the paper, is the policy analyzer able to perform several types of analysis. Specifically, our policy analyzer combines the advantages of existing MTBDD-based and SAT-solver-based techniques. Our experimental results, also reported in the paper, demonstrate the efficiency of our analyzer.
机译:当具有不同访问控制策略的各方需要参与协作应用程序和联盟时,策略集成和互操作通常是至关重要的要求。对于动态大规模协作而言,解决这种需求甚至更加困难,因为在这种情况下,要分析和比较的访问控制策略的数量可能非常大。策略整合和互操作中的重要一步是分析策略的相似性。策略相似性有时也可能是建立协作的先决条件,因为只有在另一方执行的策略匹配或非常接近其自己的策略时,一方才可以与另一方进行协作。解决和比较访问控制策略问题的现有方法非常有限,因为它们仅处理某些特殊情况。通过认识到合适的策略分析和比较方法需要结合不同的方法,我们在本文中提出了一种全面的环境考试。该环境支持各种类型的分析查询,我们在本文中对其进行了分类。我们在本文中重点介绍的这种环境的关键组成部分是能够执行多种类型分析的策略分析器。具体来说,我们的策略分析器结合了现有基于MTBDD和基于SAT求解器的技术的优势。我们的实验结果也在论文中有所报道,证明了我们分析仪的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号