首页> 外文OA文献 >X-FEDERATE: A Policy Engineering Framework for Federated Access Management
【2h】

X-FEDERATE: A Policy Engineering Framework for Federated Access Management

机译:X-FEDERATE:联合访问管理的策略工程框架

摘要

Policy-Based Management (PBM) has been considered as a promising approach for design and enforcement of access management policies for distributed systems. The increasing shift toward federated information sharing in the organizational landscape, however, calls for revisiting current PBM approaches to satisfy the unique security requirements of the federated paradigm. This presents a twofold challenge for the design of a PBM approach, where, on the one hand, the policy must incorporate the access management needs of the individual systems, while, on the other hand, the policies across multiple systems must be designed in such a manner that they can be uniformly developed, deployed, and integrated within the federated system. In this paper, we analyze the impact of security management challenges on policy design and formulate a policy engineering methodology based on principles of software engineering to develop a PBM solution for federated systems. We present X-FEDERATE, a policy engineering framework for federated access management using an extension of the well-known Role-Based Access Control (RBAC) model. Our framework consists of an XML-based policy specification language, its UML-based meta-model, and an enforcement architecture. We provide a comparison of our framework with related approaches and highlight its significance for federated access management. The paper also presents a federation protocol and discusses a prototype of our framework that implements the protocol in a federated digital library environment.
机译:基于策略的管理(PBM)被认为是设计和实施分布式系统访问管理策略的一种有前途的方法。但是,在组织环境中,越来越多的朝着联邦信息共享的方向转变,要求重新审视当前的PBM方法,以满足联邦范式的独特安全要求。这给设计PBM方法带来了双重挑战,一方面,策略必须包含各个系统的访问管理需求,另一方面,必须在这样的环境中设计跨多个系统的策略。一种可以在联合系统中统一开发,部署和集成它们的方式。在本文中,我们分析了安全管理挑战对策略设计的影响,并基于软件工程原理制定了策略工程方法论,以开发用于联邦系统的PBM解决方案。我们介绍X-FEDERATE,这是一种使用著名的基于角色的访问控制(RBAC)模型的扩展的联合访问管理的策略工程框架。我们的框架由基于XML的策略规范语言,基于UML的元模型和实施体系结构组成。我们将我们的框架与相关方法进行比较,并强调其对联合访问管理的重要性。本文还提出了联合协议,并讨论了在联合数字图书馆环境中实现该协议的我们框架的原型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号