首页> 外文OA文献 >Entity-Based Access Control: supporting more expressive access control policies
【2h】

Entity-Based Access Control: supporting more expressive access control policies

机译:基于实体的访问控制:支持更具表现力的访问控制策略

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Access control is an important part of security that restricts the actions that users can perform on resources. Policy models specify how these restrictions are formulated in policies. Over the last decades, we have seen several such models, including role-based access control and more recently, attribute-based access control.However, these models do not take into account the relationships between users, resources and entities and their corresponding properties. This limits the expressiveness of these models.In this work, we present Entity-Based Access Control (EBAC). EBAC introduces entities as a primary concept and takes into account both attributes and relationships to evaluate policies. In addition, we present Auctoritas. Auctoritas is a authorization system that provides a practical policy language and evaluation engine for EBAC.We find that EBAC increases the expressiveness of policies and fits the application domain well. Moreover, our evaluation shows that entity-based policies described in Auctoritas can be enforced with a low policy evaluation latency.
机译:访问控制是安全性的重要组成部分,它限制了用户可以对资源执行的操作。策略模型指定策略中如何制定这些限制。在过去的几十年中,我们已经看到了几种这样的模型,包括基于角色的访问控制和最近的基于属性的访问控制,但是这些模型没有考虑用户,资源和实体及其对应属性之间的关系。这限制了这些模型的表达。在这项工作中,我们提出了基于实体的访问控制(EBAC)。 EBAC引入实体作为主要概念,并同时考虑属性和关系来评估策略。另外,我们介绍Auctoritas。 Auctoritas是一个授权系统,为EBAC提供了一种实用的策略语言和评估引擎。我们发现EBAC可以提高策略的表达能力,并很好地适合应用领域。此外,我们的评估表明,Auctoritas中描述的基于实体的策略可以以较低的策略评估延迟来执行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号