首页> 外国专利> Generating role-based access control policies based on discovered risk-averse roles

Generating role-based access control policies based on discovered risk-averse roles

机译:根据发现的规避风险的角色生成基于角色的访问控制策略

摘要

Generating role-based access control policies is provided. A user-permission relation is generated by extracting users and permissions assigned to each of the users from a stored access control policy. A user-attribute relation is generated by mapping the users to attributes describing the users. A permission-attribute relation is generated by mapping the permissions to attributes describing the permissions. The set of risk-averse roles, assignment of the set of risk-averse roles to the users, and assignment of the permissions to the set of risk-averse roles are determined based on applying a risk-optimization function to the generated user-permission relation, the generated user-attribute relation, and the generated permission-attribute relation. A role-based access control policy that minimizes a risk profile of the set of risk-averse roles, the assignment of the set of risk-averse roles to the users, and the assignment of the permissions to the set of risk-averse roles is generated.
机译:提供了生成基于角色的访问控制策略。通过从存储的访问控制策略中提取用户和分配给每个用户的权限来生成用户权限关系。通过将用户映射到描述用户的属性来生成用户属性关系。通过将权限映射到描述权限的属性来生成权限属性关系。基于将风险优化功能应用于所生成的用户权限,确定风险规避角色集,向用户分配风险规避角色集以及向风险规避角色集授予权限关系,生成的用户属性关系和生成的权限属性关系。一种基于角色的访问控制策略,它最大程度地减少了规避风险的角色集,将规避风险的角色集分配给用户以及对权限规避了对规避风险的角色集的权限产生。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号