Conceptual foundations for a model of task-based authorizations

Conceptual foundations for a model of task-based authorizations
复制标题

基于任务的授权模型的概念基础

DOI:
--
复制
发表时间:
1994
期刊:
Proceedings The Computer Security Foundations Workshop VII
影响因子:
--
通讯作者:
Roshan K. Thomas
Roshan K. Thomas
中科院分区:
--
文献类型:
--
作者:
R. Sandhu;Roshan K. Thomas

文献摘要

被引文献

相似文献

我们描述的概念基础,以解决完整性问题的计算机化信息系统从企业的角度来看。这一努力的动机源于认识到,现有的模型制定在太低的抽象层次,是有用的建模组织的需求,政策方面,和内部控制,有关维护信息系统的完整性。特别地,这些模型主要关注计算机系统内的内部数据组件的完整性,因此缺乏对企业级完整性原则进行建模所必需的构造。调查的起点是与企业中执行的业务活动相关的授权功能和任务的概念。这些功能确定授权要求,而授权任务则体现执行此类授权所需的概念。我们相信,基于任务的授权模式将弥合低级别模式和非常高级别模式之间的现有差距,从纯粹的组织和社会学角度看待诚信,与计算机系统没有任何直接联系。所描述的工作是初步的和概念性的,但它是最终开发正式模型的必要先决条件。&lt;<ETX>&gt;
We describe conceptual foundations to address integrity issues in computerized information systems from the enterprise perspective. The motivation for this effort stems from the recognition that existing models are formulated at too low a level of abstraction, to be useful for modeling organizational requirements, policy aspects, and internal controls, pertaining to maintenance of integrity in information systems. In particular, these models are primarily concerned with the integrity of internal data components within computer systems, and thus lack the constructs necessary to model enterprise level integrity principles. The starting point in the investigation is the notion of authorization functions and tasks associated with business activities carried out in the enterprise. These functions identify the authorization requirements while the authorization tasks embody the concepts required to carry out such authorizations. We believe a model of task-based authorizations will bridge the existing gap between low-level models and very high level ones looking at integrity from a purely organizational and sociological perspective devoid of any direct links to computerized systems. The work described is preliminary and conceptual in nature, but is a necessary prerequisite for the eventual development of a formal model.<<ETX>>