首页> 外文OA文献 >A rigorous framework for specification, analysis and enforcement of access control policies
【2h】

A rigorous framework for specification, analysis and enforcement of access control policies

机译:用于访问控制策略的规范,分析和实施的严格框架

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Access control systems are widely used means for the protection of computing systems. They are defined in terms of access control policies regulating the access to system resources. In this paper, we introduce a formally-defined, fully-implemented framework for specification, analysis and enforcement of attribute-based access control policies. The framework rests on FACPL, a language with a compact, yet expressive, syntax for specification of real-world access control policies and with a rigorously defined denotational semantics. The framework enables the automated verification of properties regarding both the authorisations enforced by single policies and the relationships among multiple policies. Effectiveness and performance of the analysis rely on a semantic-preserving representation of FACPL policies in terms of SMT formulae and on the use of efficient SMT solvers. Our analysis approach explicitly addresses some crucial aspects of policy evaluation, such as missing attributes, erroneous values and obligations, which are instead overlooked in other proposals. The framework is supported by Java-based tools, among which an Eclipse-based IDE offering a tailored development and analysis environment for FACPL policies and a Java library for policy enforcement. We illustrate the framework and its formal ingredients by means of an e-Health case study, while its effectiveness is assessed by means of performance stress tests and experiments on a well-established benchmark.
机译:访问控制系统被广泛用于保护计算系统。根据用于控制对系统资源的访问的访问控制策略来定义它们。在本文中,我们介绍了一个正式定义的,完全实现的框架,用于规范,分析和实施基于属性的访问控制策略。该框架基于FACPL,这是一种语言,具有用于规范现实世界中的访问控制策略的紧凑但富有表现力的语法,并具有严格定义的指称语义。该框架可以自动验证有关单个策略强制执行的授权以及多个策略之间的关系的属性。分析的有效性和性能依赖于FACPL策略在SMT公式上保留语义的表示形式以及有效SMT求解器的使用。我们的分析方法明确地解决了政策评估的一些关键方面,例如缺少属性,错误的价值观和义务,而在其他建议中却忽略了这些方面。该框架由基于Java的工具支持,其中基于Eclipse的IDE为FACPL策略提供了量身定制的开发和分析环境,并为策略实施提供了Java库。我们通过电子医疗案例研究说明了该框架及其正式组成部分,而其有效性是通过性能压力测试和基于公认基准的实验进行评估的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号