A user-centered, modular authorization service built on an RBAC foundation

A user-centered, modular authorization service built on an RBAC foundation
复制标题

建立在RBAC基础上的以用户为中心的模块化授权服务

DOI:
--
复制
发表时间:
1999
期刊:
Proceedings of the 1999 IEEE Symposium on Security and Privacy (Cat. No.99CB36344)
影响因子:
--
通讯作者:
T. Sanfilippo
T. Sanfilippo
中科院分区:
--
文献类型:
--
作者:
M. Zurko;Richard T. Simon;T. Sanfilippo

文献摘要

被引文献

相似文献

心理可接受性已经被提到作为安全系统的要求,只要最小的特权和故障安全默认值,但直到现在,在安全系统的实际设计中几乎被忽略了。我们将这一原则置于Adage设计的中心,Adage是分布式应用程序的授权服务。我们采用可用性设计技术来指定和测试我们的授权语言和相应的管理GUI的功能。我们的测试结果加强了我们的初始设计中心,并为我们的授权服务的部署提供了建议。模块化架构允许我们在短期集成期间对设计进行实验,并将其发展为长期探索。RBAC基础支持灵活的授权约束和查询的一致设计。我们讨论的经验教训,从实施这项服务,通过有计划的部署的背景下,必须平衡新的研究风险管理与依赖于遗留服务。
Psychological acceptability has been mentioned as a requirement for secure systems for as long as least privilege and fail safe defaults, but until now has been all but ignored in the actual design of secure systems. We place this principle at the center of our design for Adage, an authorization service for distributed applications. We employ usability design techniques to specify and test the features of our authorization language and the corresponding administrative GUI. Our testing results reinforce our initial design center and suggest directions for deployment of our authorization services. A modular architecture allows us to experiment with our design during short term integration, and evolve it for longer term exploration. An RBAC foundation enables coherent design of flexible authorization constraints and queries. We discuss lessons learned from the implementation of this service through a planned deployment in a context that must balance new research in risk management with dependencies on legacy services.