首页> 外国专利> PROVISIONING ACCESS CONTROL USING SDDL ON THE BASIS OF AN XACML POLICY

PROVISIONING ACCESS CONTROL USING SDDL ON THE BASIS OF AN XACML POLICY

机译:基于XACML政策使用SDDL进行访问控制

摘要

A method is disclosed, and a corresponding data carrier and policy converter, for producing at least one Security Descriptor Definition Language, SDDL, rule from an eXtensible Access Control Markup Language, XACML, policy (P), wherein said at least one SDDL rule is enforceable for controlling access to one or more resources in a computer network. A reverse query is produced indicating a given decision (d), which is one of permit access and deny access, and a set (R) of admissible access requests. Based on the reverse query, the XACML policy (P) and the given decision (d) are translated into a satisfiable logic proposition in Boolean variables (vi, i=1, 2, . . . ) From said ROBDD, variable assignments (RCj=[ARCj1:v1=xj1, ARCj2:v2=xj2, . . . ], j=1, 2, . . . ) satisfying the logic proposition are derived and at least one SDDL rule is created based on said variable assignments (RCj=[ARCj1:v1=xj1, ARCj2:v2=xj2, . . . ], j=1, 2, . . . ) satisfying the logic proposition.
机译:公开了一种方法,以及相应的数据载体和策略转换器,用于从可扩展访问控制标记语言XACML策略(P)产生至少一种安全描述符定义语言SDDL规则,其中,所述至少一个SDDL规则为可执行以控制对计算机网络中一个或多个资源的访问。产生反向查询,指示给定的决定(d)和允许的访问请求集(R),该决定是许可访问和拒绝访问之一。基于反向查询,将XACML策略(P)和给定的决策(d)转换为布尔变量(v i ,i = 1,2,....)中可满足的逻辑命题。从所述ROBDD中,变量分配(RC j = [ARC j1 :v 1 = x j1 ,ARC <导出满足逻辑命题的Sub> j2 :v 2 = x j2 ,。。。,j = 1,2,。。。根据所述变量分配创建至少一个SDDL规则(RC j = [ARC j1 :v 1 = x j1 < / Sub>,ARC j2 :v 2 = x j2 ,。。。],j = 1,2,。逻辑命题。

著录项

  • 公开/公告号US2015163250A1

    专利类型

  • 公开/公告日2015-06-11

    原文格式PDF

  • 申请/专利权人 AXIOMATICS AB;

    申请/专利号US201514623311

  • 申请日2015-02-16

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 15:27:02

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号