PL EN


Preferencje help
Widoczny [Schowaj] Abstrakt
Liczba wyników
Tytuł artykułu

RTT+ - Time Validity Constraints in RTT Language

Treść / Zawartość
Identyfikatory
Warianty tytułu
Języki publikacji
EN
Abstrakty
EN
Most of the traditional access control models, like mandatory, discretionary and role based access control make authorization decisions based on the identity, or the role of the requester, who must be known to the resource owner. Thus, they may be suitable for centralized systems but not for decentralized environments, where the requester and service provider or resource owner are often unknown to each other. To overcome the shortcomings of traditional access control models, trust management models have been presented. The topic of this paper is three different semantics (set-theoretic, operational, and logic- programming) of RTT , language from the family of role-based trust management languages (RT). RT is used for representing security policies and credentials in decentralized, distributed access control systems. A credential provides information about the privileges of users and the security policies issued by one or more trusted authorities. The set-theoretic semantics maps roles to a set of sets of entity names. Members of such a set must cooperate in order to satisfy the role. In the case of logic-programming semantics, the credentials are translated into a logic program. In the operational semantics the credentials can be established using a simple set of inference rules. It turns out to be fundamental mainly in large- scale distributed systems, where users have only partial view of their execution context. The core part of this paper is the introduction of time validity constraints to show how that can make RTT language more realistic. The new language, named RTT+ takes time validity constraints into account. The semantics for RTT+ language will also be shown. Inference system will be introduced not just for specific moment but also for time intervals. It will evaluate maximal time validity, when it is possible to derive the credential from the set of available credentials. The soundness and completeness of the inference systems with the time validity constraints with respect to the set-theoretic semantics of RTT+ will be proven.
Rocznik
Tom
Strony
74--82
Opis fizyczny
Bibliogr. 26 poz.
Twórcy
autor
Bibliografia
  • [1] D. F. Ferraiolo, R. S. Sandhu, S. I. Gavrila, D. R. Kuhn, and R. Chandramouli, “Proposed NIST standard for role-based access control”, ACM Trans. Inf. Syst. Secur., no. 3, pp. 224–274, 2001.
  • [2] R. S. Sandhu, E. J. Coyne, H. L. Feinstein, and C. E. Youman, “Role-based access control models”, IEEE Computer, no. 2, pp. 38–47, 1996.
  • [3] M. Blaze, J. Feigenbaum, and J. Lacy, “Decentralized trust management”, in Proc. 17th IEEE Symp. Secur. Privacy, Oakland, CA, USA, 1996, pp. 164–173.
  • [4] W. M. Grudzewski, I. K. Hejduk, A. Sankowska, and M. Wańtuchowicz, Trust Management in Virtual Work Environments: A Human Factors Perspective. CRC Press Taylor & Francis Group, 2008.
  • [5] N. Li and J. Mitchell, “RT: a role-based trust-management framework”, in Proc. 3rd DARPA Inform. Surviv. Conf. Exp., IEEE Computer Society Press, Oakland, CA, USA, 2003, pp. 201–212.
  • [6] N. Li, J. Mitchell, and W. Winsborough, “Design of a role-based trust-management framework”, in Proc. IEEE Symp. Secur. Privacy, IEEE Computer Society Press, Oakland, CA, USA, 2002, pp. 114–130.
  • [7] N. Li, W. Winsborough, and J. Mitchell, “Distributed credential chain discovery in trust management”, J. Comput. Secur., no. 1, pp. 35–86, 2003.
  • [8] D. Gorla, M. Hennessy, and V. Sassone, “Inferring dynamic credentials for role-based trust management”, in Proc. 8th ACM SIGPLAN Conf. Princip. Pract. Declar. Program. PPDP 2006, Venice, Italy, 2006, pp. 213–224.
  • [9] A. Felkner and K. Sacha, “The semantics of role-based trust management languages”, in Proc. CEE-SET 2009, Kraków, Poland, 2009, pp. 195–206, (preprints).
  • [10] A. Felkner and K. Sacha, “Deriving RTT credentials for role-based trust management”, e-Inf. Softw. Engin. J., vol. 4, pp. 9–19, 2010.
  • [11] M. Blaze, J. Feigenbaum, and M. Strauss, “Compliance checking in the policymaker trust management system”, in Proc. 2nd Int. Conf. Financial Cryptography, London, United Kingdom, 1998, pp. 254–274.
  • [12] M. Blaze, J. Feigenbaum, and A. D. Keromytis, “The role of trust management in distributed systems security”, in Secure Internet Pro- gramming, J. Vitek, C. D. Jensen, Eds. Springer, 1999, pp. 185–210.
  • [13] D. Clarke, J.-E. Elien, C. Ellison, M. Fredette, A. Morcos, and R. L. Rivest, “Certificate chain discovery in SPKI/SDSI”, J. Comp. Secur., no. 9, pp. 285–322, 2001.
  • [14] P. Chapin, C. Skalka, and X. S. Wang, “Authorization in trust management: features and foundations”, ACM Comp. Surv., no. 3, pp. 1–48, 2008.
  • [15] M. R. Czenko, S. Etalle, D. Li, and W. H. Winsborough, “An In- troduction to the Role Based Trust Management Framework RT”, Tech. Rep. TR-CTIT-07-34, Centre for Telematics and Information Technology University of Twente, Enschede, 2007.
Typ dokumentu
Bibliografia
Identyfikator YADDA
bwmeta1.element.baztech-article-BATA-0016-0009
JavaScript jest wyłączony w Twojej przeglądarce internetowej. Włącz go, a następnie odśwież stronę, aby móc w pełni z niej korzystać.