首页> 外文OA文献 >Modularity and Dynamic Adaptation of Flexibly Secure Systems: Model-Driven Adaptive Delegation in Access Control Management
【2h】

Modularity and Dynamic Adaptation of Flexibly Secure Systems: Model-Driven Adaptive Delegation in Access Control Management

机译:灵活安全系统的模块化和动态适应:访问控制管理中的模型驱动自适应委托

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Model-Driven Security (Mds) is a specialized Model-Driven Engineering (Mde) approach for supporting the development of secure systems. Model-Driven Security aims at improving the productivity of the development process and quality of the resulting secure systems, with models as the main artifact. Among the variety of models that have been studied in a Model-Driven Security perspective, one canmention access control models that specify the access rights. So far, these models mainly focus on static definitions of access control policies, without taking into account the more complex, but essential, delegation of rights mechanism. Delegation is a meta-level mechanism for administrating access rights, which allows a user without any specific administrative privileges to delegate his/her access rights to another user. This paper gives a formalization of access control and delegation mechanisms, and analyses the main hard-points for introducing various advanced delegation semantics in Model-Driven Security. Then, we propose a modular model-driven framework for 1) specifying access control, delegation and the business logic as separate concerns; 2) dynamically enforcing/weaving access control policies with various delegation features into security-critical systems; and 3) providing a flexibly dynamic adaptation strategy.We demonstrate the feasibility and effectiveness of our proposed solution through the proof-of-concept implementations of different component-based systems running on different adaptive execution platforms, i.e. OSGi and Kevoree.
机译:模型驱动的安全性(Mds)是一种专门的模型驱动工程(Mde)方法,用于支持安全系统的开发。基于模型的安全性旨在以模型为主要工件,从而提高开发过程的生产率和所得安全系统的质量。在“模型驱动的安全性”透视图中研究的各种模型中,有一种指定访问权限的分类访问控制模型。到目前为止,这些模型主要集中在访问控制策略的静态定义上,而不考虑更复杂但必不可少的权限委派机制。委派是用于管理访问权限的元级别机制,它允许没有任何特定管理特权的用户将他/她的访问权限委派给另一个用户。本文给出了访问控制和委派机制的形式,并分析了在模型驱动的安全性中引入各种高级委派语义的主要难点。然后,我们为以下方面提出一个模块化的模型驱动框架:1)将访问控制,委派和业务逻辑指定为单独的关注点; 2)将具有各种委派功能的访问控制策略动态实施/编织到安全关键的系统中; 3)提供灵活的动态适应策略。我们通过在不同的自适应执行平台(即OSGi和Kevoree)上运行的不同基于组件的系统的概念验证实现,论证了我们提出的解决方案的可行性和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号