The Role of Trust Management in Distributed Systems Security

The Role of Trust Management in Distributed Systems Security
复制标题

DOI:
10.1007/3-540-48749-2_8
复制
发表时间:
2001-06
期刊:
--
影响因子:
--
通讯作者:
M. Blaze;J. Feigenbaum;A. Keromytis
M. Blaze;J. Feigenbaum;A. Keromytis
中科院分区:
其他
文献类型:
--
作者:
M. Blaze;J. Feigenbaum;A. Keromytis

文献摘要

被引文献

相似文献

现有的授权机制无法提供强大而健壮的工具来处理当今互联网所需的规模的安全性。由于开发和部署了提高互联网可编程性的系统,这些机制正面临越来越大的压力。此外,这种“通过可编程性增加灵活性”的趋势似乎正在加速的建议,如主动网络和移动的Agents的出现。信任管理引擎避免了在授权决策中解析“身份”的需要。相反,它们用编程语言表达特权和限制。这允许增加灵活性和可表达性,以及现代可扩展安全机制的标准化。信任管理方法的进一步优势包括证明所请求的事务符合本地策略和系统架构,鼓励开发人员和管理员仔细考虑应用程序的安全策略,并明确指定它。我们介绍了信任管理的概念,解释了其基本原理,并描述了一些现有的信任管理引擎,包括PolicyMakerandKeyNote。我们还报告我们的经验,在几个分布式系统应用程序中使用信任管理引擎。
Existing authorization mechanisms fail to provide powerful and robust tools for handling security at the scale necessary for today’s Internet. These mechanisms are coming under increasing strain from the development and deployment of systems that increase the programmability of the Internet. Moreover, this “increased flexibility through programmability” trend seems to be accelerating with the advent of proposals such as Active Networking and Mobile Agents.Thetrust-management approachto distributed-system security was developed as an answer to the inadequacy of traditional authorization mechanisms. Trust-management engines avoid the need to resolve “identities” in an authorization decision. Instead, they express privileges and restrictions in a programming language. This allows for increased flexibility and expressibility, as well as standardization of modern, scalable security mechanisms. Further advantages of the trust-management approach include proofs that requested transactions comply with local policies and system architectures that encourage developers and administrators to consider an application’s security policy carefully and specify it explicitly.In this paper, we examine existing authorization mechanisms and their inadequacies. We introduce the concept of trust management, explain its basic principles, and describe some existing trust-management engines, includingPolicyMakerandKeyNote. We also report on our experience using trust-management engines in several distributed-system applications.