首页> 外文会议>IEEE International Workshop on Factory Communication Systems >Toward attribute-based access control policy in industrial networked systems
【24h】

Toward attribute-based access control policy in industrial networked systems

机译:面向工业网络系统中基于属性的访问控制策略

获取原文

摘要

The definition of a correct Access Control Policy is a fundamental step in the design of a secure information system. However, the complexity of modern systems makes critical the choice upon which model to use for such definition. This is becoming particularly true for Industrial Networked Systems, where a correct access control policy must cover all the different and ever evolving interactions between all of its heterogeneous sub-systems at different levels of the production process. In this paper, with the support of an example of a typical industrial system, we highlight the limitations of the well known and widely used Role Based Access Control policy model and we propose an alternative model, built on the ideas of the Attribute Based Access Control model, showing how it can be leveraged to easily define complex access control policies in Industrial Networked Systems. We provide also a preliminary analysis on the kind of conflicts or anomalies that such expressive model can introduce.
机译:正确的访问控制策略的定义是安全信息系统设计中的基本步骤。但是,现代系统的复杂性使选择哪种模型用于此类定义变得至关重要。对于工业网络系统来说尤其如此,在该系统中,正确的访问控制策略必须涵盖在生产过程的不同级别上其所有异构子系统之间所有不同且不断发展的交互。在本文中,在一个典型的工业系统示例的支持下,我们强调了众所周知且广泛使用的基于角色的访问控制策略模型的局限性,并基于基于属性的访问控制的思想,提出了一种替代模型。模型,展示了如何利用它轻松地在工业联网系统中定义复杂的访问控制策略。我们还对这种表达模型可能引入的冲突或异常类型进行了初步分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号