首页> 外文OA文献 >Budget-aware role based access control
【2h】

Budget-aware role based access control

机译:基于预算感知角色的访问控制

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

The suitability of Role Based Access Control (RBAC) is being challenged in dynamic environments like healthcare. In an RBAC system, a user's legitimate access may be denied if their need has not been anticipated by the security administrator at the time of policy specification. Alternatively, even when the policy is correctly specified an authorised user may accidentally or intentionally misuse the granted permission. The heart of the challenge is the intrinsic unpredictability of users' operational needs as well as their incentives to misuse permissions. In this paper we propose a novel Budget-aware Role Based Access Control (B-RBAC) model that extends RBAC with the explicit notion of budget and cost, where users are assigned a limited budget through which they pay for the cost of permissions they need. We propose a model where the value of resources are explicitly defined and an RBAC policy is used as a reference point to discriminate the price of access permissions, as opposed to representing hard and fast rules for making access decisions. This approach has several desirable properties. It enables users to acquire unassigned permissions if they deem them necessary. However, users misuse capability is always bounded by their allocated budget and is further adjustable through the discrimination of permission prices. Finally, it provides a uniform mechanism for the detection and prevention of misuses.
机译:在诸如医疗保健之类的动态环境中,基于角色的访问控制(RBAC)的适用性正受到挑战。在RBAC系统中,如果在制定策略时安全管理员未预期到用户的需求,则可能拒绝该用户的合法访问。或者,即使正确地指定了策略,授权用户也可能会意外或有意滥用授予的权限。挑战的核心是用户操作需求固有的不可预测性以及他们滥用权限的动机。在本文中,我们提出了一种新颖的基于预算的基于角色的访问控制(B-RBAC)模型,该模型以明确的预算和成本概念扩展了RBAC,在该模型中,为用户分配了有限的预算,他们通过这些预算来支付所需的权限费用。我们提出了一个模型,在该模型中明确定义了资源的价值,并且使用RBAC策略作为区分访问权限价格的参考点,而不是代表制定访问决策的硬性规则和快速规则。这种方法具有几个理想的属性。它使用户认为必要时可以获得未分配的权限。但是,用户滥用能力始终受其分配的预算限制,并且可以通过区分许可价格来进一步调整。最后,它提供了一种检测和防止滥用的统一机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号