首页> 外文学位 >Role-based access control for trust management: Model, processes, and management.
【24h】

Role-based access control for trust management: Model, processes, and management.

机译:基于角色的信任管理访问控制:模型,流程和管理。

获取原文
获取原文并翻译 | 示例

摘要

Role-based access control (RBAC) has been widely accepted within computer security communities over the last decade.; The primary goal of this dissertation work is to provide an integrated mechanism for facilitating role-based authorization in open and distributed environments. For the purpose, we first propose a role-based access control model for trust management called TRUSTr. TRUSTr introduces a new component called trust assignment (TA) to traditional RBAC models, thereby associating roles in a local domain with roles from trusted domains. Central to understand TA is that capability delegation across domains can be expressed on the basis of roles associated by TA.; After discussing how roles can be used for access control in open and distributed environments by presenting a trust-enabled RBAC model, we further investigate two important issues relevant to the usage of roles: how valid roles can be defined and how defined roles can be managed systematically for access control. Role engineering (RE) is an approach to defining roles and assigning permissions to roles, whereby an organizational access control policy can be formulated on roles. We present an RE framework called SIREN for enabling process-driven role definition. The core of our framework is that informational characteristics and flows in the process of RE are analyzed, and then, system-centric information is modeled for the purpose of providing both a method of analysis and a method of communication between two authority boundaries identified in the process of RE. Unified Modeling Language (UML) extension mechanisms are exploited for modeling the information. A case study of using the information model is described to demonstrate its feasibility. Role administration (RA) is an approach to managing defined roles. We propose three methodological constituents that enable systematic role management. We also describe a role administration system called RolePartner, which is built on the top of those methodological constituents. RolePartner leverages a directory service for storing role-based authorization policies. We demonstrate that the system can be seamlessly integrated into an existing privilege-based authorization infrastructure based on trust management. (Abstract shortened by UMI.)
机译:在过去的十年中,基于角色的访问控制(RBAC)已在计算机安全社区中被广泛接受。学位论文的主要目的是提供一个集成的机制,以促进在开放和分布式环境中基于角色的授权。为此,我们首先提出一种用于信任管理的基于角色的访问控制模型,称为TRUSTr。 TRUSTr在传统的RBAC模型中引入了一个称为信任分配(TA)的新组件,从而将本地域中的角色与来自受信任域的角色相关联。了解TA的核心是跨域的能力委派可以基于TA关联的角色来表达。在通过介绍启用信任的RBAC模型讨论了如何在开放和分布式环境中将角色用于访问控制之后,我们进一步研究了与角色使用相关的两个重要问题:如何定义有效角色以及如何管理定义的角色系统地进行访问控制。角色工程(RE)是一种定义角色并向角色分配权限的方法,从而可以在角色上制定组织访问控制策略。我们提出了一个称为SIREN的RE框架,用于启用流程驱动的角色定义。我们框架的核心是分析可再生能源过程中的信息特征和流程,然后对以系统为中心的信息进行建模,以提供分析方法和在授权过程中确定的两个权限边界之间的通信方法。 RE的过程。利用统一建模语言(UML)扩展机制对信息进行建模。描述了使用信息模型的案例研究,以证明其可行性。角色管理(RA)是一种管理已定义角色的方法。我们提出了三种能够实现系统角色管理的方法论要素。我们还描述了一个称为RolePartner的角色管理系统,该系统建立在这些方法组成部分的顶部。 RolePartner利用目录服务来存储基于角色的授权策略。我们证明了该系统可以无缝集成到基于信任管理的现有基于权限的授权基础结构中。 (摘要由UMI缩短。)

著录项

  • 作者

    Shin, Dongwan.;

  • 作者单位

    The University of North Carolina at Charlotte.;

  • 授予单位 The University of North Carolina at Charlotte.;
  • 学科 Computer Science.; Information Science.
  • 学位 Ph.D.
  • 年度 2005
  • 页码 107 p.
  • 总页数 107
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;信息与知识传播;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号