首页> 外文期刊>International Journal of Computer Systems Science & Engineering >A framework for modelling restricted delegation of rights in the Sectet
【24h】

A framework for modelling restricted delegation of rights in the Sectet

机译:在“秘密”中建立有限授权模型的框架

获取原文
获取原文并翻译 | 示例
           

摘要

We present a novel approach for modelling restricted delegation of rights in a distributed environment based on web services. In existing delegation models, delegated permissions are statically assigned to a role which is not the case in Service Oriented Architecture's (SOA). In SOA, permissions to execute web services are delegated to roles with a set of dynamic constraints. These constraints play a key role in the assignment of permissions to roles. This paper presents an extension to our model Constraint based Role Based Access Control (CRBAC), CRBAC1, in order to support permission-level delegation based on dynamic constraints. Our approach integrates Sectet-PL, a predicative language for modelling access rights based on the concept of Role Based Access Control (RBAC). Sectet-PL is part of the Sectet framework for model-driven security for B2B workflows. Our Rights Delegation Model combines the concept of roles from RBAC with the predicative specification of Sectet-PL. The Rights Delegation Model is translated into XACML Delegation Policies, which are interpreted by a security gateway.
机译:我们提出了一种新颖的方法,用于在基于Web服务的分布式环境中对受限的权利委派进行建模。在现有的委托模型中,将委托权限静态地分配给角色,而在面向服务的体系结构(SOA)中则不是这种情况。在SOA中,将执行Web服务的权限委派给具有一组动态约束的角色。这些约束在角色权限分配中起着关键作用。本文提出了对我们的基于约束的基于角色的访问控制(CRBAC)模型CRBAC1的扩展,以支持基于动态约束的权限级别委派。我们的方法集成了Sectet-PL,​​这是一种基于角色访问控制(RBAC)概念的用于对访问权限进行建模的预测性语言。 Sectet-PL是Sectet框架的一部分,该框架用于B2B工作流的模型驱动的安全性。我们的权利委派模型将RBAC角色的概念与Sectet-PL的谓词规范相结合。权限委派模型被转换为XACML委派策略,由安全网关解释。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号