首页> 外文OA文献 >The Flask Security Architecture: System Support for Diverse Security Policies
【2h】

The Flask Security Architecture: System Support for Diverse Security Policies

机译:Flask安全体系结构:多种安全策略的系统支持

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Operating systems must be flexible in their support for security policies, providing sufficient mechanisms for supporting the wide variety of real-world security policies. Such flexibility requires controlling the propagation of access rights, enforcing fine-grained access rights and supporting the revocation of previously granted access rights. Previous systems are lacking in at least one of these areas. In this paper we present an operating system security architecture that solves these problems. Control over propagation is provided by ensuring that the security policy is consulted for every security decision. This control is achieved without significant performance degradation through the use of a security decision caching mechanism that ensures a consistent view of policy decisions. Both fine-grained access rights and revocation support are provided by mechanisms that are directly integrated into the service-providing components of the system. The architecture is described through its prototype implementation in the Flask microkernel-based operating system, and the policy flexibility of the prototype is evaluated. We present initial evidence that the architecture\u27s impact on both performance and code complexity is modest. Moreover, our architecture is applicable to many other types of operating systems and environments.
机译:操作系统必须灵活支持安全策略,并提供足够的机制来支持各种实际的安全策略。这种灵活性要求控制访问权限的传播,执行细粒度的访问权限并支持撤销先前授予的访问权限。这些领域中至少有一个缺少先前的系统。在本文中,我们提出了解决这些问题的操作系统安全体系结构。通过确保为每个安全决策都参考安全策略来提供对传播的控制。通过使用确保策略决策的一致视图的安全决策缓存机制,可以在不显着降低性能的情况下实现此控制。通过直接集成到系统的服务提供组件中的机制来提供细粒度的访问权限和吊销支持。通过在基于Flask微内核的操作系统中实现其原型来描述该体系结构,并评估该原型的策略灵活性。我们提供的初步证据表明,该体系结构对性能和代码复杂性的影响是适度的。此外,我们的体系结构适用于许多其他类型的操作系统和环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号