首页> 外文会议>Microwave and Millimetre Wave Monolithic Integrated Circuits >A layered design of discretionary access controls with decidable safety properties
【24h】

A layered design of discretionary access controls with decidable safety properties

机译:具有可确定的安全属性的自由访问控制的分层设计

获取原文
获取原文并翻译 | 示例

摘要

An access control design can be viewed as a three layered entity: the general access control model; the parameterization of the access control model; and the initial users and objects of the system before it goes live. The design of this three-tiered mechanism can be evaluated according to two broad measures, the expressiveness versus the complexity of the system. In particular, the question arises: What security properties can be expressed and verified? We present a general access control model which can be parameterized at the second layer to implement (express) any of the standard Discretionary Access Control (DAC) models. We show that the safety problem is decidable for any access control model implemented using our general access control model. Until now, all general access control models that were known to be sufficiently expressive to implement the full range of DAC models had an undecidable safety problem. Thus, given our model all of the standard DAC models (plus many others) can be implemented in a system in which their safety properties are decidable.
机译:可以将访问控制设计视为三层实体:通用访问控制模型;访问控制模型的参数化;以及系统上线之前的初始用户和对象。这种三层机制的设计可以根据两个广泛的指标进行评估,即表达性与系统复杂性。特别是出现了一个问题:可以表达和验证哪些安全属性?我们提出了一种通用访问控制模型,可以在第二层对其进行参数化,以实现(表达)任何标准的自由裁量访问控制(DAC)模型。我们表明,对于使用我们的通用访问控制模型实现的任何访问控制模型,安全问题都是可以确定的。到现在为止,所有已知具有足够表达能力以实现所有DAC模型的通用访问控制模型都存在不确定的安全问题。因此,给定我们的模型,所有标准DAC模型(以及许多其他模型)都可以在可确定其安全性的系统中实施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号