首页> 外文期刊>International Journal of Information Security >Handling distributed authorization with delegation through answer set programming
【24h】

Handling distributed authorization with delegation through answer set programming

机译:通过答案集编程处理带委派的分布式授权

获取原文
获取原文并翻译 | 示例
           

摘要

Distributed authorization is an essential issue in computer security. Recent research shows that trust management is a promising approach for the authorization in distributed environments. There are two key issues for a trust management system: how to design an expressive high-level policy language and how to solve the compliance-checking problem (Blaze et al. in Proceedings of the Symposium on Security and Privacy, pp. 164–173, 1996; Proceedings of 2nd International Conference on Financial Cryptography (FC’98). LNCS, vol.1465, pp. 254–274, 1998), where ordinary logic programming has been used to formalize various distributed authorization policies (Li et al. in Proceedings of the 2002 IEEE Symposium on Security and Privacy, pp. 114–130, 2002; ACM Trans. Inf. Syst. Secur. (TISSEC) 6(1):128–171, 2003). In this paper, we employ Answer Set Programming to deal with many complex issues associated with the distributed authorization along the trust management approach. In particular, we propose a formal authorization language AL providing its semantics through Answer Set Programming. Using language , we cannot only express nonmonotonic delegation policies which have not been considered in previous approaches, but also represent the delegation with depth, separation of duty, and positive and negative authorizations. We also investigate basic computational properties related to our approach. Through two case studies. we further illustrate the application of our approach in distributed environments.
机译:分布式授权是计算机安全中的重要问题。最近的研究表明,信任管理是一种在分布式环境中进行授权的有前途的方法。信任管理系统有两个关键问题:如何设计一种表达力强的高级策略语言以及如何解决合规性检查问题(Blaze等人在“安全和隐私研讨会论文集”,第164-173页) (1996年;第二届国际金融密码学会议论文集(FC'98)。LNCS,第1465卷,第254-274页,1998年),其中普通逻辑编程已用于形式化各种分布式授权策略(Li等。 (2002年IEEE安全与隐私专题研讨会论文集,第114-130页; ACM跨系统信息安全(TISSEC)6(1):128-171,2003年)。在本文中,我们采用“答案集编程”来处理与信任管理方法中的分布式授权相关的许多复杂问题。特别是,我们提出了一种形式化的授权语言AL,该语言通过Answer Set Programming提供了其语义。使用语言,我们不仅可以表达以前的方法中未曾考虑过的非单调委派政策,而且还以深度,职责分离以及正面和负面的授权来代表代表团。我们还将研究与我们的方法有关的基本计算属性。通过两个案例研究。我们进一步说明了我们的方法在分布式环境中的应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号