首页> 外文会议>Business and Information Management, 2008. ISBIM '08 >Separation of Duty Constraint for Permission Based Delegation Model
【24h】

Separation of Duty Constraint for Permission Based Delegation Model

机译:基于权限的委托模型的职责约束分离

获取原文

摘要

In large enterprise software systems, users often need to delegate their authority to others. Permission base delegation model (PBDM) based on RBAC96 currently is the most attractive model to fulfill the delegation requirement since it supports partly delegation and multiple steps delegation. However in PBDM there is no explicit specification of the separation of duty (SOD) constraint, which is one of the most important constraints and is essential to the security of the system. In this paper, we analyze the SOD constraint in PBDM delegation model and give the formal definition for the constraint. We prove that the constraint violation will not happen at the stage of the delegation role definition whereas it can only happen at the stage of role assignment. We then propose a protective mechanism to prevent the illegal role delegation utilizing the prerequisite conditions which are a set of Boolean expressions. We also give the algorithm to check the prerequisite conditions to help the security administrator guarantee the safe role delegation.
机译:在大型企业软件系统中,用户经常需要将其权限委派给其他人。基于RBAC96的权限基础委托模型(PBDM)当前是满足委托要求的最有吸引力的模型,因为它支持部分委托和多步委托。但是,在PBDM中,没有明确的职责分离(SOD)约束规范,SOD约束是最重要的约束之一,对于系统的安全性至关重要。在本文中,我们分析了PBDM委托模型中的SOD约束,并给出了约束的正式定义。我们证明约束冲突不会在委托角色定义阶段发生,而只能在角色分配阶段发生。然后,我们提出一种保护机制,以利用作为一组布尔表达式的先决条件来防止非法角色委派。我们还给出了检查前提条件的算法,以帮助安全管理员确保安全角色委派。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号