Managing attribute-based access control policies in a unified framework using data warehousing and in-memory database

Managing attribute-based access control policies in a unified framework using data warehousing and in-memory database
复制标题

DOI:
10.1016/j.cose.2019.06.001
复制
发表时间:
2019-06
影响因子:
5.6
通讯作者:
M. Singh;S. Sural;Jaideep Vaidya;V. Atluri
M. Singh;S. Sural;Jaideep Vaidya;V. Atluri
中科院分区:
计算机科学3区
文献类型:
--
作者:
M. Singh;S. Sural;Jaideep Vaidya;V. Atluri

文献摘要

被引文献

相似文献

在过去的几年里,各种类型的访问控制模型已经提出来表达组织不断增长的需求。其中,越来越多的人对使用基于属性的访问控制(ABAC)的灵活和动态决策安全策略的规范和实施感兴趣。但是,将不同模型中指定的现有安全策略迁移到ABAC中并不容易。此外,不存在可以指定、实施和管理ABAC策略沿着组织中可能已经存在的其他策略作为统一安全策略的综合方法。在本文中,我们提出了一种独特而灵活的解决方案,通过在多维和多粒度数据模型中存储和查询数据,可以同时指定和执行此类安全策略。具体来说,我们提出了一个统一的数据库模式,类似于传统上使用的数据仓库设计,可以代表不同类型的访问控制策略和存储相关的政策作为内存中的数据,从而显着减少访问请求评估的执行时间。我们还提出了一种新的方法,通过元策略相结合的多个访问控制策略。为了便于管理,提出了一个管理模式,可以指定不同类型的管理策略。广泛的数据集上的大量实验证明了所提出的方法的可行性。
Over the last few years, various types of access control models have been proposed for expressing the growing needs of organizations. Out of these, there is an increasing interest towards specification and enforcement of flexible and dynamic decision making security policies using Attribute Based Access Control (ABAC). However, it is not easy to migrate an existing security policy specified in a different model into ABAC. Furthermore, there exists no comprehensive approach that can specify, enforce and manage ABAC policies along with other policies potentially already existing in the organization as a unified security policy. In this article, we present a unique and flexible solution that enables concurrent specification and enforcement of such security policies through storing and querying data in a multi-dimensional and multi-granular data model. Specifically, we present a unified database schema, similar to that traditionally used in data warehouse design, that can represent different types of access control policies and store relevant policies as in-memory data, thereby significantly reducing the execution time of access request evaluation. We also present a novel approach for combining multiple access control policies through meta-policies. For ease of management, an administrative schema is presented that can specify different types of administrative policies. Extensive experiments on a wide range of data sets demonstrate the viability of the proposed approach.