Computer access control policy choices

Computer access control policy choices
复制标题

计算机访问控制策略选择

DOI:
10.1016/0167-4048(90)90113-8
复制
发表时间:
1990
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
M. Abrams
M. Abrams
中科院分区:
--
文献类型:
--
作者:
Ingrid M. Olson;M. Abrams

文献摘要

被引文献

相似文献

本文提供了一个指南-路线图-提炼成一个可实施的访问控制策略的高层次的信息传播/控制政策。此过程涉及确定一组适当的面向策略的限制,并且可以在多个级别上进行,从最高级别的公司决策到硬件实现选择。本文讨论了在这个过程中需要做出的许多选择,以及做出每个决定的一些影响。访问控制的通用框架(GFAC),一个正在进行的研究工作的讨论,提出了一个框架和新的角度来描述访问控制。自由裁量权访问控制和强制性访问控制的GFAC框架内进行了描述,并给出了两个例子,显示如何改变一些政策的选择可以代表不同的政策,可能会满足不同的访问控制要求。
This paper provides a guide—a road map—for refining a high-level information dissemination/control policy into an implementable access control policy. This process involves determining the appropriate set of policy-oriented limitations and can take place at many levels, from a top-level corporate decision to a hardware implementation choice. The paper discusses many of the choices that need to be made in the process and some of the implications of making each decision. A discussion of the Generalized Framework for Access Control (GFAC), an ongoing research effort, presents a framework and new perspective for describing access controls. Discretionary Access Control and Mandatory Access Control are described within the GFAC framework, and two examples are given showing how changing some of the policy choices can represent a different policy which may meet a different set of access control requirements.