首页> 外文OA文献 >Design and Implementation of Virtual Private Services
【2h】

Design and Implementation of Virtual Private Services

机译:虚拟私人服务的设计与实现

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Large scale distributed applications such as electronic commerce and online marketplaces combine network access with multiple storage and computational elements. The distributed responsibility for resource control creates new security and privacy issues, which are exacerbated by the complexity of the operating environment. In order to handle policies at multiple locations, the usual tools available (firewalls and compartmented file storage) get to be used in ways that are clumsy and prone to failure. We propose a new approach, virtual private services. Our approach relies on two functional divisions. First, we split policy specification and policy enforcement, providing local autonomy within the constraints of the global security policy. Second, we create virtual security domains, each with its own security policy. Every domain has an associated set of privileges and permissions restricting it to the resources it needs to use and the services it must perform. Virtual private services ensure security and privacy policies are adhered to through coordinated policy enforcement points. We describe our architecture and a prototype implementation, and present a preliminary performance evaluation confirming that our overhead of policy enforcement using is small.
机译:诸如电子商务和在线市场等大型分布式应用程序将网络访问与多个存储和计算元素结合在一起。分散的资源控制责任产生了新的安全性和隐私问题,操作环境的复杂性加剧了这一问题。为了在多个位置处理策略,可用的常用工具(防火墙和分隔文件存储)以笨拙且容易出现故障的方式使用。我们提出了一种新的方法,虚拟私人服务。我们的方法依赖于两个功能部门。首先,我们将策略规范和策略执行分开,在全局安全策略的约束范围内提供本地自治。其次,我们创建虚拟安全域,每个域都有自己的安全策略。每个域都有一组相关的特权和权限,将其限制为需要使用的资源和必须执行的服务。虚拟专用服务可通过协调的策略执行点确保遵守安全和隐私策略。我们描述了我们的体系结构和原型实现,并提出了初步的性能评估,以确认我们使用策略执行的开销很小。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号