首页> 外文期刊>International Journal of Information Security >Understanding SPKI/SDSI using first-order logic
【24h】

Understanding SPKI/SDSI using first-order logic

机译:使用一阶逻辑了解SPKI / SDSI

获取原文
获取原文并翻译 | 示例
           

摘要

SPKI/SDSI is a language for expressing distributed access control policy, derived from SPKI and SDSI. We provide a first-order logic (FOL) semantics for SDSI, and show that it has several advantages over previous semantics. For example, the FOL semantics is easily extended to additional policy concepts and gives meaning to a larger class of access control and other policy analysis queries. We prove that the FOL semantics is equivalent to the string rewriting semantics used by SDSI designers, for all queries associated with the rewriting semantics. We also provide a FOL semantics for SPKI/SDSI and use it to analyze the design of SPKI/SDSI. This reveals some problems. For example, the standard proof procedure in RFC 2693 is semantically incomplete. In addition, as noted before by other authors, authorization tags in SPKI/SDSI are algorithmically problematic, making a complete proof procedure unlikely. We compare SPKI/SDSI with RT 1 C , which is a language in the RTRole-based Trust-management framework that can be viewed as an extension of SDSI. The constraint feature of RT 1 C , based on Constraint Datalog, provides an alternative mechanism that is expressively similar to SPKI/SDSI tags, semantically natural, and algorithmically tractable.
机译:SPKI / SDSI是一种语言,用于表达源自SPKI和SDSI的分布式访问控制策略。我们为SDSI提供了一阶逻辑(FOL)语义,并证明了它比以前的语义具有多个优势。例如,FOL语义很容易扩展到其他策略概念,并为更广泛的访问控制和其他策略分析查询赋予含义。对于与重写语义相关联的所有查询,我们证明FOL语义等效于SDSI设计人员使用的字符串重写语义。我们还为SPKI / SDSI提供FOL语义,并使用它来分析SPKI / SDSI的设计。这揭示了一些问题。例如,RFC 2693中的标准证明程序在语义上是不完整的。另外,正如其他作者之前所指出的那样,SPKI / SDSI中的授权标签在算法上存在问题,因此不太可能使用完整的证明程序。我们将SPKI / SDSI与RT 1 C进行了比较,RT 1 C是基于RTRole的信任管理框架中的一种语言,可以视为SDSI的扩展。 RT 1 C的约束功能基于Constraint Datalog,提供了一种替代机制,该机制在表达上类似于SPKI / SDSI标签,在语义上自然且在算法上易处理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号