期刊文献+

多域间动态角色转换的职责分离 被引量:14

Separation of Duty in Dynamic Role Translations Between Administrative Domains
下载PDF
导出
摘要 两个或多个管理域间的安全互操作是一个重要的研究课题·Kapadia等人提出的IRBAC2000模型通过动态角色转换灵活地实现了域间安全互操作·在IRBAC2000模型中每个管理域均采用RBAC模型,职责分离是RBAC模型支持的最基本的3个安全原则之一,并可用一组静态互斥角色约束来表示·而IRBAC2000模型没有考虑职责分离·因此,对动态角色转换违背静态互斥角色约束的各种情形进行了详细分析,并抽象出各种情形的本质特征;对动态角色转换是否会违背静态互斥角色约束提供了一种判定方法并给出了相应的算法;提出了使用先决条件来加强IRBAC2000模型安全性的保护机制· Secure interaction and interoperability between two or more administrative domains is d major concern. Kapadia et al. proposed the IRBAC 2000 model, which can be used to accomplish flexibly dynamic inter-domain role translations. However, in the IRBAC 2000 model, separation of duties is not considered, which is one of three basic security principles supported by the RBAC model, and enforced by statically mutually exclusive role constraints. Therefore, in this paper, the scenarios where dynamic role translations violate statically mutually exclusive role constraints are analyzed in detail, an approach to check the security problem is provided, and a protective mechanism utilizing prerequisite conditions to enforce the security of the IRBAC 2000 model is proposed.
出处 《计算机研究与发展》 EI CSCD 北大核心 2006年第6期1065-1070,共6页 Journal of Computer Research and Development
基金 国家自然科学基金项目(60403027)~~
关键词 IRBAC 2000模型 动态角色转换 互斥角色 先决条件 IRBAC 2000 model dynamic role translation mutually exclusive roles prerequisite conditions
  • 相关文献

参考文献8

  • 1Apu Kapadia, Jalal AI-Muhtadi, R. Campbell, et al. IRBAC 2000: Secure interoperability using dynamic role translation.University of Illinois, Technical Report: UIUCDCS-R-2000-2162, 2000
  • 2Ravi S. Sandhu, Edward J. Coyne, Hal L. Feinstein, et al.Role-based access control models. IEEE Computer, 1996, 29(2):38-47
  • 3G, Malkin, Internet users'glossary. IETF RFC 1983. http://www. faqs. org/rfcs/rfc1983.html, 1996
  • 4D. F. Ferraiolo, R. S. Sandhu, S. Gavrila, et al. Proposed NIST standard for role-based access control. ACM Trans.Information and Systems Security, 2001, 4(3): 224-274
  • 5J, Crampton. Specifying and enforcing constraints in role-based access control. In: Proc, 8th ACM Symposium on Access Control Models and Technologies. New York: ACM Press, 2003. 43-50
  • 6Ninghui Li, Ziad Bizri, Mahesh V. Tripunitara. On mutually-exclusive roles and separation of duty. In: Proc. 11th Conf.Computer and Communications Security. New York: ACM Press,2004. 42-51
  • 7Ravi Sandhu, Qamar Munawer. The ARBAC99 model for administration of roles. In: Proc. 15th Annual Computer Security Applications Conference. Los Alamitos, CA: IEEE Computer Society Press, 1999. 229-239
  • 8Ravi Sandhu, Venkata Bhamidipati, Qamar Munawer. The ARBAC97 model for role-based administration of roles. ACM Trans. Information and System Security, 1999, 2 ( 1 ) : 105 - 135

同被引文献187

引证文献14

二级引证文献28

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部