Separation of duty in role-based environments

被引:134
作者
Simon, RT
Zurko, ME
机构
来源
10TH COMPUTER SECURITY FOUNDATIONS WORKSHOP, PROCEEDINGS | 1997年
关键词
D O I
10.1109/CSFW.1997.596811
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Separation of Duty is a principle that has a long history, in computer security research. Many computing systems provide rudimentary support for this principle, but often the support is inconsistent with the way the principle is applied in non-computing environments. Furthermore, there appears to be no single accepted meaning of the term. We examine the ways in which Separation of Duty has been used, adding the notion of History-based Separation of Duty. We assess ways in which computing systems may support Separation of Duty. We discuss the mechanisms we are implementing to support Separation of Duty and roles in Adage, a general-purpose authorization language and toolkit.
引用
收藏
页码:183 / 194
页数:12
相关论文
empty
未找到相关数据