课题基金 / 基金详情

HCC-Small: Collaborative Mixed-Initiative Access Control

HCC-Small: Collaborative Mixed-Initiative Access Control
HCC-Small:协作混合主动访问控制
批准号:
0810861
负责人:
Prasun Dewan
金额:
$41.02万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2008
资助国家:
美国
项目状态:
已结题
起止时间:
2008-09-01 至 2015-08-31

项目摘要

项目成果

Prasun Dewan的其他基金

相似基金

相关文献

中文摘要
翻译
今天,我们面临着三个明显相互矛盾的问题:用户害怕协作,除非他们对其他人如何访问他们的数据有细粒度的控制;许多共享环境,特别是新环境,不提供这样的控制,因为实现它们很困难;那些提供此类控制的控件提供了难以理解和使用的访问机制,并导致用户被分配错误的访问权限。在这个项目中,PI将研究使用特殊用途的协作环境来分发访问的想法,其目标是开发一个访问分发的通用模型,该模型捕获到目前为止仅以依赖于应用程序的方式定义的正在使用的和有前途的混合计划。该模型将使用几种新的独立于应用程序的对象来定义,例如访问请求和授权,它们捕获混合主动系统中交换的信息。它将与现有的授权模型兼容,包括基于对象的模型(其中授予对象副本)和基于权限的模型(例如基于角色的访问控制),其中授予对象的权限(可能可撤销)。在PI的方法中,向共享对象分发访问权限的主动性可以由信息监护人、信息消费者和充当监护人和消费者代理的工具承担。信息消费者有责任向信息监护人提出访问请求;他们的代理将(部分或完全)为他们自动完成这项任务。信息监护人负责授权访问;他们的代理将为他们自动完成这项任务。PI将为实现他的模型确定一个通用架构,在这个架构中,现有协作和通信工具中的访问意识保持在较低水平。此外,PI将开发编程抽象,使使用体系结构实现模型变得容易。他将使用抽象在几个目标系统中添加混合主动访问控制,这些目标系统将包括复杂的广泛使用的传统文件系统和分布式web服务;这种经验将帮助PI评估抽象的可编程性。最后,他将进行实地和实验室研究,以比较通用模型支持的分配访问的替代方法。更广泛的影响:如果成功,这项工作将开辟一个新的研究领域,专注于协作混合主动访问控制,并表明协作系统不仅是访问控制的负担,也是一种资产。项目结果将显著改善细粒度授权机制的可用性和可编程性,从而促进大量协作,否则这些协作将不会发生。它们还有助于更好地理解不同访问分配方案之间的异同以及使用它们的后果。在短期内,该项目将开发由两个主要组件组成的研究和教学软件:广泛使用的文件系统之上的层,提供几种新的访问分配方案,可以由可用性研究人员进行评估并在安全性课程中进行演示;编程抽象允许将这些方案合并到使用web服务实现的新共享环境中,这可以在课堂和研究项目中使用。
英文摘要
Today, we are faced with three apparently conflicting problems: users are afraid to collaborate unless they have fine-grained control over how their data are accessed by others; many shared environments, especially the new ones, do not offer such controls because of the difficulty of implementing them; those that do offer such controls provide access mechanisms that are difficult to understand and use and result in users being assigned wrong access rights. In this project the PI will investigate the idea of using special-purpose collaborative environments to distribute access, with the goal of developing a general model of access distribution that captures in-use and promising mixed-initiative schemes that have so far been defined only in an application-dependent fashion. The model will be defined using several new kinds of application-independent objects such as access requests and grants that capture the information exchanged in a mixed-initiative system. It will be compatible with existing authorization models including object-based models, in which copies of objects are granted, and rights-based models such as role-based access control, in which (potentially revocable) rights to the object granted. In the PI's approach, the initiative in distributing access rights to shared objects can be taken by information guardians, information consumers, and tools that act as agents of the guardians and the consumers. Information consumers are responsible for sending access requests to information guardians; their agents will (partially or completely) automate this task for them. Information guardians are responsible for authorizing access; their agents will automate this task for them. The PI will identify a general architecture for implementing his model, in which the access-awareness in existing collaboration and communication tools is kept low. In addition, the PI will develop programming abstractions that make it easy to implement the model using the architecture. He will use the abstractions to add mixed-initiative access control in several target systems, which will include both complex widely-used traditional file systems and distributed web services; this experience will help the PI evaluate the programmability of the abstractions. Finally, he will perform field and lab studies to compare alternative approaches to distribute access supported by the general model. Broader Impacts: If successful, this work will open up a new research area focusing on collaborative mixed-initiative access control, and show that collaborative systems are not only a liability for access control but also an asset. Project outcomes will lead to significant improvement in the usability and programmability of fine-grained authorization mechanisms, thereby facilitating a large number of collaborations that would otherwise not take place. They will also afford a better understanding of the similarities and differences between different access distribution schemes and the consequences of using them. In the short term, the project will develop research and teaching software consisting of two main components: layers on top of widely-used file systems that provide several new access distribution schemes, which can be evaluated by usability researchers and demonstrated in classes on security; and programming abstractions allowing the incorporation of these schemes in new shared environments implemented using web services, which can be used in both class and research projects.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: CyberTraining: Pilot: Semi-Automatic Assessment of Parallel Programs in Training of Students and Faculty
Collaborative Research: CyberTraining: CIU: Toward Distributed and Scalable Personalized Cyber-Training
EAGER: Automatic Classification of Programming Difficulties by Mining Programming Events
HCC: Evaluating the Performance of Distributed Synchronous Collaboration Architectures
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: