首页> 外文期刊>International Journal of Information Security >A uniform approach for access control and business models with explicit rule realization
【24h】

A uniform approach for access control and business models with explicit rule realization

机译:具有显式规则实现的访问控制和业务模型的统一方法

获取原文
获取原文并翻译 | 示例
           

摘要

Access control is an important part of security in software, such as business applications, since it determines the access of users to objects and operations and the constraints of this access. Business and access control models are expressed using different representations. In addition, access control rules are not generally defined explicitly from access control models. Even though the business model and access control model are two separate modeling abstractions, they are inter-connected as access control is part of any business model. Therefore, the first goal is to add access control models to business models using the same fundamental building blocks. The second goal is to use these models and define general access control rules explicitly from these models so that the connection between models and their realizations are also present. This paper describes a new common representation for business models and classes of access control models based on the Resource-Event-Agent (REA) modeling approach to business models. In addition, the connection between models and their represented rules is clearly defined. We present a uniform approach to business and access control models. First, access control primitives are mapped onto REA-based access control patterns. Then, REA-based access control patterns are combined to define access control models. Based on these models, general access control rules are expressed in Extended Backus-Naur Form.
机译:访问控制是软件(例如业务应用程序)中安全性的重要组成部分,因为它决定了用户对对象和操作的访问权限以及访问权限的限制。业务和访问控制模型使用不同的表示形式表示。此外,通常不会从访问控制模型中明确定义访问控制规则。尽管业务模型和访问控制模型是两个单独的建模抽象,但是它们是相互关联的,因为访问控制是任何业务模型的一部分。因此,首要目标是使用相同的基本构件将访问控制模型添加到业务模型中。第二个目标是使用这些模型,并从这些模型中明确定义一般的访问控制规则,以使模型及其实现之间也存在联系。本文介绍了一种基于资源-事件-代理(REA)建模方法的业务模型和访问控制模型类的新通用表示形式。此外,模型及其表示的规则之间的联系也得到了明确定义。我们为业务和访问控制模型提供了一种统一的方法。首先,将访问控制原语映射到基于REA的访问控制模式。然后,将基于REA的访问控制模式进行组合以定义访问控制模型。基于这些模型,一般的访问控制规则以扩展Backus-Naur形式表示。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号