首页> 外文会议>European Symposium on Research in Computer Security; 20050912-14; Milan(IT) >A Generic XACML Based Declarative Authorization Scheme for Java Architecture and Implementation
【24h】

A Generic XACML Based Declarative Authorization Scheme for Java Architecture and Implementation

机译:基于通用XACML的Java体系结构的声明性授权方案和实现

获取原文
获取原文并翻译 | 示例

摘要

Security and authorization play a very important role in the development, deployment and functioning of software systems. Java being the most popular platform for component-based software and systems, Java security is playing a key role in enterprise systems. The major drawback in the security support provided by J2EE and J2SE is the absence of a standard way to support instance level access control. JAAS does provide some help, but it is not without its share of problems. The newest standard related to security - XACML, provides a standard simple way to represent security policies. In the paper we propose a unique way to extend JAAS technology so that it can support class-instance level access control in a declarative manner. We then showcase how this extension can be molded in the XACML architecture, thereby providing an end-to-end standard based access control specification and implementation for J2SE and J2EE applications. The major advantage of our technique is that, being declarative it does not require any change to the security code when - either the security policies are changed or the security infrastructure is deployed in a new environment.
机译:安全和授权在软件系统的开发,部署和功能中起着非常重要的作用。 Java是基于组件的软件和系统最流行的平台,Java安全性在企业系统中扮演着关键角色。 J2EE和J2SE提供的安全性支持的主要缺点是缺少支持实例级访问控制的标准方法。 JAAS确实提供了一些帮助,但并非没有问题。与安全相关的最新标准XACML提供了表示安全策略的标准简单方法。在本文中,我们提出了一种扩展JAAS技术的独特方法,使其可以以声明的方式支持类实例级别的访问控制。然后,我们展示了如何在XACML体系结构中模制此扩展,从而为J2SE和J2EE应用程序提供了基于端到端标准的访问控制规范和实现。我们的技术的主要优势在于,声明性地,在更改安全策略或在新环境中部署安全基础结构时,不需要更改安全代码。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号