Object-to-Object Relationship-Based Access Control: Model and Multi-Cloud Demonstration (Invited Paper)

Object-to-Object Relationship-Based Access Control: Model and Multi-Cloud Demonstration (Invited Paper)
复制标题

基于对象到对象关系的访问控制:模型和多云演示(特邀论文)

DOI:
--
复制
发表时间:
2016
期刊:
IEEE International Conference on Information Reuse and Integration
影响因子:
--
通讯作者:
R. Sandhu
R. Sandhu
中科院分区:
--
文献类型:
--
作者:
Tahmina Ahmed;Farhan Patwa;R. Sandhu

文献摘要

被引文献

相似文献

自在线社交网络(OSNs)出现以来,基于关系的访问控制(Relationship Based Access Control,ReBAC)被认为是一种独特的访问控制形式。在OSN上下文中,ReBAC通常根据用户之间的人际关系来表达授权策略。受OSN启发的ReBAC模型主要关注用户到用户的关系,尽管有些模型也考虑了用户到资源和资源到资源的关系。一个OSN有非常具体的资源类型(照片,评论,笔记等)。这些资源与用户密切相关,因此很自然地认为OSN中的资源关系是通过用户发生的。然而,独立于用户的资源到资源(或对象到对象)关系在信息系统中已经存在了几十年。例如,面向对象的系统维护对象之间的继承、组合和关联关系,版本控制系统使用不同版本之间的派生关系,而数字内容管理系统使用不同媒体文件之间的基本关系。据我们所知,没有现有的ReBAC模型考虑对象之间的用户独立的通用关系,作为一种有用的手段来表达授权策略。本文提出了一种新的对象到对象ReBAC模型(OOReBAC),它使用对象关系来控制对对象的访问。我们使用开源OpenStack云平台,特别是其Swift对象存储服务,构建了OOReBAC的概念验证实现。
Relationship Based Access Control (ReBAC) has been recognized as a distinctive form of access control since the advent of online social networks (OSNs). In the OSN context, ReBAC typically expresses authorization policy in terms of interpersonal relationship between users. OSN-inspired ReBAC models primarily focus on user-to-user relationships, although some have also considered user-to-resource and resource-to-resource relationships. An OSN has very specific type of resources (photos, comments, notes etc.) which are closely related to users, so it is natural to consider resource relationships in OSNs as occurring through users. However user-independent resource-to-resource (or object-to-object) relationships have been around for decades in information systems. For instance, object-oriented systems maintain inheritance, composition and association relationships among objects, version control systems use derived-from relationships between different versions, and digital content management systems use fundamental-relationships between different media files. To our knowledge no existing ReBAC model considers user-independent generic relationships between objects, as a useful means to express authorization policies. This paper proposes a novel Object-to-Object ReBAC model (OOReBAC) which uses object relationships for controlling access to objects. We build a proof-of-concept implementation of OOReBAC using the open source OpenStack cloud platform and specifically its Swift object storage service.