Meta-policies for distributed role-based access control systems

被引:16
作者
Belokosztolszki, A [1 ]
Moody, K [1 ]
机构
[1] Univ Cambridge, Comp Lab, Cambridge, England
来源
THIRD INTERNATION WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS | 2002年
关键词
D O I
10.1109/POLICY.2002.1011298
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper meta-policies for access control policies are presented. There has been a lot of research into the various ways of specifying policy for a single domain. Such domains are autonomous and can be managed by the users or by a specific system administrator It is often helpful to have a more general policy description in order to restrict the ways in which policy can be modified. Meta-policies fill this particular role. With their help changes to policy can be made subject to predefined constraints. Meta-policies are long lived and so can provide users with stable information about the policy of the system. In addition they can provide bodies external to a domain with relevant but restricted information about its policies, so forming a basis for co-operation between domains. For example, a domain's meta-policy can function as a policy interface, thus establishing a basis for agreement on the structure of the objects accessed. In this way it is possible to build service level agreements between domains automatically.
引用
收藏
页码:106 / 115
页数:10
相关论文
共 21 条
[1]  
[Anonymous], 2001, 6 ACM S ACCESS CONTR
[2]  
[Anonymous], 1999, ACM T INFORM SYSTEMS
[3]  
AWISCHUS R, 1997, P 2 ACM WORKSH ROL B, P61
[4]  
BACON J, 2001, MIDDLEWARE 2001, V2218, P300
[5]  
Damianou N, 2001, LECT NOTES COMPUT SC, V1995, P18
[6]   A formal model for role-based access control with constraints [J].
Giuri, L ;
Iglio, P .
9TH IEEE COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS, 1996, :136-145
[7]   On the formal definition of separation-of-duty policies and their composition [J].
Gligor, VD ;
Gavrila, SI ;
Ferraiolo, D .
1998 IEEE SYMPOSIUM ON SECURITY AND PRIVACY - PROCEEDINGS, 1998, :172-183
[8]  
HAYTON R, 1996, 399 U CAMBR
[9]  
KANG MH, 2001, 6 ACM S ACC CONTR MO
[10]  
KOCH M, 2001, 6 ACM S ACC CONTR MO, P121