透過您的圖書館登入
IP:18.191.88.249
  • 期刊

A Policy-Oriented Language for Expressing Security Specifications

並列摘要


Organizations' authorization policies are usually described by access control rules enforced on each protected object scattered all over the organization. Having a single global security policy specification would promote both security clarity and coherency [4, 9, 18, 31, 37]. Having a single security model for the whole organization, a single point of management and enforcement with a innumerous set of unknown users, does not scale well. However, both the policy enforcement and the mapping of unknown users to known entities [28] can be decoupled from the specification; thus, having a single global security policy decoupled from the enforcement and from the mapping of unknown users promotes clarity and coherency without compromising scalability. This work presents a security policy language which is able to express simultaneously many different types of models, which is essential to handle all the policies used on a complex organization. The proposed language can express the concepts of permission and prohibition, and some restricted forms of obligation. We show how to express and implement obligation using the transaction concept. We also address the problem of incoherent policies and show how to efficiently enforce the security policies expressed by the language with a security access monitor, implemented in java, including history-based and obligation-based security policies.

並列關鍵字

Authorization coherency history obligation policy

被引用紀錄


徐子涵(2016)。墨西哥石油業發展及當前所面臨的困境與改革策略〔碩士論文,淡江大學〕。華藝線上圖書館。https://doi.org/10.6846/TKU.2016.00435
蔡坤曄(2006)。苯在Pt/Hβ的開環及異構化反應研究〔碩士論文,國立清華大學〕。華藝線上圖書館。https://doi.org/10.6843/NTHU.2006.00114
Wu, J. P. (2014). 不交叉近似法於雙渠道贗能隙安德森模型之應用:量子臨界與統一標度律 [master's thesis, National Chiao Tung University]. Airiti Library. https://doi.org/10.6842/NCTU.2014.00032
林大鈞(2011)。自組式第一型量子環與第二型量子點之磁場光學研究〔博士論文,國立交通大學〕。華藝線上圖書館。https://doi.org/10.6842/NCTU.2011.00296
謝建銘(2009)。以桿狀病毒表現系統生產A型肉毒桿菌毒素做為疫苗可行性的分析〔碩士論文,中原大學〕。華藝線上圖書館。https://doi.org/10.6840/cycu200901190

延伸閱讀