首页> 外文OA文献 >Dynamic Scoping for Browser Based Access Control System
【2h】

Dynamic Scoping for Browser Based Access Control System

机译:基于浏览器的访问控制系统的动态作用域

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

We have inorganically increased the use of web applications to the point of using them for almost everything and making them an essential part of our everyday lives. As a result, the enhancement of privacy and security policies for the web applications is becoming increasingly essential. The importance and stateless nature of the web infrastructure made the web a preferred target of attacks. The current web access control system is a reason behind the victory of attacks. The current web consists of two major components, the browser and the server, where the effective access control system needs to be implemented. In terms of an access control system, the current web has adopted the inadequate same origin policy and same session policy for the browser and server, respectively. The current web access control system policies are sufficient for the earlier dayu27s web, which became inadequate to address the protection needs of todayu27s web.In order to protect the web application from un-trusted contents, we provide an enhanced browser based access control system by enabling the dynamic scoping. Our security model for the browser will allow the client and trusted web application contents to share a common library and protect web contents from each other, while they still get executed at different trust levels. We have implemented a working model of an enhanced browser based access control system in Java, under the Lobo browser.
机译:我们无机地增加了对Web应用程序的使用,以至于几乎可以将它们用于所有事物,并使它们成为我们日常生活的重要组成部分。结果,增强Web应用程序的隐私和安全策略变得越来越重要。 Web基础结构的重要性和无状态性质使Web成为攻击的首选目标。当前的Web访问控制系统是攻击取得成功的原因。当前的Web由浏览器和服务器两个主要组件组成,需要在其中实现有效的访问控制系统。在访问控制系统方面,当前的网络分别针对浏览器和服务器采用了不足的相同原始策略和相同会话策略。当前的Web访问控制系统策略足以满足早期Web的需求,但不足以满足当今Web的保护需求。为了保护Web应用程序免受不受信任的内容的侵扰,我们提供了一种基于浏览器的增强功能通过启用动态作用域来访问控制系统。我们针对浏览器的安全模型将允许客户端和受信任的Web应用程序内容共享一个公共库并相互保护Web内容,而它们仍将以不同的信任级别执行。我们已经在Lobo浏览器下用Java实现了基于浏览器的增强访问控制系统的工作模型。

著录项

  • 作者

    Nadipelly Vinaykumar;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号