首页> 外文会议>European Symposium on Research in Computer Security(ESORICS 2004); 20040913-15; Sophia Antipolis(FR) >Incorporating Dynamic Constraints in the Flexible Authorization Framework
【24h】

Incorporating Dynamic Constraints in the Flexible Authorization Framework

机译:将动态约束纳入灵活授权框架

获取原文
获取原文并翻译 | 示例

摘要

Constraints are an integral part of access control policies. De-pending upon their time of enforcement, they are categorized as static or dynamic; static constraints are enforced during the policy compilation time, and the dynamic constraints are enforced during run time. While there are several logic-based access control policy frameworks, they have a limited power in expressing and enforcing constraints (especially the dynamic constraints). We propose dynFAF, a constraint logic program-ming based approach for expressing and enforcing constraints. To make it more concrete, we present our approach as an extension to the flexible authorization framework (FAF) of Jajodia et ai. We show that dynFAF satisfies standard safety and liveliness properties of a safety conscious software system.
机译:约束是访问控制策略的组成部分。视其执行时间而定,它们分为静态或动态两种。在策略编译期间强制执行静态约束,而在运行时强制执行动态约束。尽管有几种基于逻辑的访问控制策略框架,但它们在表达和执行约束(尤其是动态约束)方面的能力有限。我们提出dynFAF,这是一种基于约束逻辑编程的方法,用于表达和执行约束。为了使其更加具体,我们将我们的方法作为对Jajodia等人的灵活授权框架(FAF)的扩展。我们表明dynFAF满足了具有安全意识的软件系统的标准安全性和活泼性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号