Guide to Attribute Based Access Control (ABAC) Definition and Considerations [includes updates as of 02-25-2019]

Guide to Attribute Based Access Control (ABAC) Definition and Considerations [includes updates as of 02-25-2019]
复制标题

基于属性的访问控制 (ABAC) 定义和注意事项指南 [包括截至 2019 年 2 月 25 日的更新]

DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
K. Scarfone
K. Scarfone
中科院分区:
--
文献类型:
--
作者:
Vincent C. Hu;David F. Ferraiolo;Rick Kuhn;Adam Schnitzer;Kenneth Sandlin;Robert Miller;K. Scarfone

文献摘要

被引文献

相似文献

本文档为联邦机构提供了基于属性的访问控制(ABAC)的定义。ABAC是一种逻辑访问控制方法,其中通过评估与主体、对象、所请求的操作相关联的属性来确定执行一组操作的授权,并且在某些情况下,根据描述给定属性集的可允许操作的策略、规则或关系来评估环境条件。本文档还提供了使用ABAC改进组织内和组织间的信息共享,同时保持对该信息的控制的注意事项。
This document provides Federal agencies with a definition of attribute based access control (ABAC). ABAC is a logical access control methodology where authorization to perform a set of operations is determined by evaluating attributes associated with the subject, object, requested operations, and, in some cases, environment conditions against policy, rules, or relationships that describe the allowable operations for a given set of attributes. This document also provides considerations for using ABAC to improve information sharing within organizations and between organizations while maintaining control of that information.