Authorization and attribute certificates for widely distributed access control

Authorization and attribute certificates for widely distributed access control
复制标题

用于广泛分布式访问控制的授权和属性证书

DOI:
10.1109/enabl.1998.725715
复制
发表时间:
1998
期刊:
Proceedings Seventh IEEE International Workshop on Enabling Technologies: Infrastucture for Collaborative Enterprises (WET ICE '98) (Cat. No.98TB100253)
影响因子:
--
通讯作者:
M. Thompson
M. Thompson
中科院分区:
--
文献类型:
--
作者:
W. Johnston;Srilekha Mudumbai;M. Thompson

文献摘要

被引文献

相似文献

作者描述了一个系统,其目的是探索使用证书的分布式管理资源的访问权限,有多个,独立的,地理上分散的利益相关者。涉众在授权证书中声明他们的使用条件,并指定那些受信任的人来证明相应的属性。这些使用条件通过对某些属性的要求隐式地定义访问组。所有使用条件必须同时满足,因此实际访问组是所有组的交集。当用户尝试访问特定资源时,策略引擎收集使用条件证书和属性证书。如果满足所有使用条件,则为资源生成能力。根据使用条件之间是否建立任何关系,策略引擎可以提供多种不同的策略模型。该系统的体系结构和实现的描述,连同一些确定的优点,缺点和漏洞。
The authors describe a system whose purpose is to explore the use of certificates for the distributed management of access rights for resources that have multiple, independent, and geographically dispersed stakeholders. The stakeholders assert their use-conditions in authorization certificates and designate those trusted to attest to the corresponding attributes. These use-conditions implicitly define access groups through their requirement for certain attributes. All use-conditions must be satisfied simultaneously, so the actual access group is the intersection of all of the groups. A policy engine collects the use-condition certificates and attribute certificates when a user attempts to access a particular resource. If all of the use-conditions are met, a capability is generated for the resource. The policy engine can provide several different policy models depending on whether any relationship is established among the use-conditions. The system architecture and implementation is described, together with some of the identified strengths, weaknesses, and vulnerabilities.