首页> 外文OA文献 >Know Why Your Access Was Denied: Regulating Feedback for Usable Security
【2h】

Know Why Your Access Was Denied: Regulating Feedback for Usable Security

机译:知道为什么拒绝访问:调整可用安全性的反馈

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。
获取外文期刊封面目录资料

摘要

We examine the problem of providing useful feedback to users who are denied access to resources, while controlling the disclosure of the system security policies. High-quality feedback enhances the usability of a system, especially when permissions may depend on contextual information---time of day, temperature of a room and other factors that change unpredictably. However, providing too much information to the user may breach the confidentiality of the system policies. To achieve a balance between system usability and privacy of security policies, we present Know, a framework that uses Ordered Binary Decision Diagrams (OBDDs) and cost functions to provide feedback to users about access control decisions. Know honors a system's privacy requirements, which are represented as a meta-policy, and generates permissible and relevant feedback to users on how to obtain access to a resource. To the best of our knowledge, our work is the first to address the need of access control feedback while honoring the privacy and confidentiality requirements of a system's security policy.
机译:我们研究了在控制系统安全策略公开的同时向拒绝访问资源的用户提供有用反馈的问题。高质量的反馈可增强系统的可用性,尤其是在权限可能取决于上下文信息(一天中的时间,房间的温度以及其他不可预测的因素)的情况下。但是,向用户提供过多信息可能会破坏系统策略的机密性。为了在系统可用性和安全策略隐私之间取得平衡,我们提出了Know(一个框架),该框架使用有序二进制决策图(OBDD)和成本函数向用户提供有关访问控制决策的反馈。 Know遵守系统的隐私要求(表示为元策略),并就如何获得对资源的访问权向用户生成允许的相关反馈。据我们所知,我们的工作是第一个在满足系统安全策略的隐私和机密性要求的同时满足访问控制反馈需求的工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号