...
首页> 外文期刊>Journal of computer security >On the formalization and analysis of a spatio-temporal role-based access control model
【24h】

On the formalization and analysis of a spatio-temporal role-based access control model

机译:基于时空角色的访问控制模型的形式化与分析

获取原文
           

摘要

With the growing use of wireless networks and mobile devices, we are moving towards an era of pervasive computing. Such environments will spawn new applications that use contextual information to provide enhanced services. Traditional access control models cannot protect such applications because the access requirements may be contingent upon the location of the user and the time of access. Consequently, we propose a new spatio-temporal role-based access control model that supports delegation for use in such applications. The model can be used by any application where the access is contingent not only on the role of the user, but also on the locations of the user and the object and the time of access. We describe how each entity in the role-based access control model is affected by time and location and propose constraints to express this. We also show how the formal semantics of our model can be expressed using graph-theoretic notation. The various features of our model give rise to numerous constraints that may interact with each other and result in conflicts. Thus, for any given application using our model, it is important to analyze the interaction of constraints to ensure that conflicts or security breaches do not occur. Manual analysis is tedious and error-prone. Towards this end, we show how the analysis can be automated using Coloured Petri Nets. Since automated analysis for large applications is time consuming, we propose an approach that reduces the analysis time.
机译:随着无线网络和移动设备的日益普及,我们正在迈入普适计算的时代。这样的环境将产生使用上下文信息来提供增强服务的新应用程序。传统的访问控制模型无法保护此类应用程序,因为访问要求可能取决于用户的位置和访问时间。因此,我们提出了一种新的基于时空角色的访问控制模型,该模型支持在此类应用程序中使用的委派。该模型可以被访问不但取决于用户角色,而且取决于用户和对象的位置以及访问时间的任何应用程序使用。我们描述了基于角色的访问控制模型中的每个实体如何受到时间和位置的影响,并提出了约束条件来表达这一点。我们还展示了如何使用图论符号来表​​达模型的形式语义。我们模型的各种特征引起了许多可能相互影响并导致冲突的约束。因此,对于使用我们模型的任何给定应用程序,重要的是分析约束的相互作用以确保不发生冲突或安全漏洞。手动分析是乏味且容易出错的。为此,我们展示了如何使用有色Petri网自动进行分析。由于大型应用程序的自动分析非常耗时,因此我们提出了一种减少分析时间的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号