Suppr超能文献

使用数据仓库和内存数据库在统一框架中管理基于属性的访问控制策略。

Managing Attribute-Based Access Control Policies in a Unified Framework using Data Warehousing and In-Memory Database.

作者信息

Singh Mahendra Pratap, Sural Shamik, Vaidya Jaideep, Atluri Vijayalakshmi

机构信息

Department of Computer Science and Engineering, Indian Institute of Technology, Kharagpur, India.

Management Science and Information Systems Department, Rutgers University, USA.

出版信息

Comput Secur. 2019 Sep;86:183-205. doi: 10.1016/j.cose.2019.06.001. Epub 2019 Jun 12.

Abstract

Over the last few years, various types of access control models have been proposed for expressing the growing needs of organizations. Out of these, there is an increasing interest towards specification and enforcement of flexible and dynamic decision making security policies using Attribute Based Access Control (ABAC). However, it is not easy to migrate an existing security policy specified in a different model into ABAC. Furthermore, there exists no comprehensive approach that can specify, enforce and manage ABAC policies along with other policies potentially already existing in the organization as a unified security policy. In this article, we present a unique and flexible solution that enables concurrent specification and enforcement of such security policies through storing and querying data in a multi-dimensional and multi-granular data model. Specifically, we present a unified database schema, similar to that traditionally used in data warehouse design, that can represent different types of access control policies and store relevant policies as in-memory data, thereby significantly reducing the execution time of access request evaluation. We also present a novel approach for combining multiple access control policies through meta-policies. For ease of management, an administrative schema is presented that can specify different types of administrative policies. Extensive experiments on a wide range of data sets demonstrate the viability of the proposed approach.

摘要

在过去几年中,为满足组织日益增长的需求,人们提出了各种类型的访问控制模型。其中,使用基于属性的访问控制(ABAC)来规范和实施灵活且动态的决策安全策略越来越受到关注。然而,将以不同模型指定的现有安全策略迁移到ABAC并非易事。此外,不存在一种全面的方法能够将ABAC策略与组织中可能已经存在的其他策略一起作为统一的安全策略进行规范、实施和管理。在本文中,我们提出了一种独特且灵活的解决方案,通过在多维多粒度数据模型中存储和查询数据,实现此类安全策略的并发规范和实施。具体而言,我们提出了一种类似于传统数据仓库设计中使用的统一数据库模式,它可以表示不同类型的访问控制策略,并将相关策略存储为内存数据,从而显著减少访问请求评估的执行时间。我们还提出了一种通过元策略组合多个访问控制策略的新颖方法。为便于管理,我们给出了一种可以指定不同类型管理策略的管理模式。在广泛数据集上进行的大量实验证明了所提方法的可行性。

相似文献

1
Managing Attribute-Based Access Control Policies in a Unified Framework using Data Warehousing and In-Memory Database.
Comput Secur. 2019 Sep;86:183-205. doi: 10.1016/j.cose.2019.06.001. Epub 2019 Jun 12.
2
Security Analysis of ABAC under an Administrative Model.
IET Inf Secur. 2019 Mar;13(2):96-103. doi: 10.1049/iet-ifs.2018.5010. Epub 2018 Oct 23.
3
Contemporaneous Update and Enforcement of ABAC Policies.
Proc ACM Symp Access Control Model Technol. 2022 Jun;2022:31-42. doi: 10.1145/3532105.3535021. Epub 2022 Jun 8.
5
Enabling the Deployment of ABAC Policies in RBAC Systems.
Data Appl Secur Priv XXXII (2018). 2018 Jul;10980:51-68. doi: 10.1007/978-3-319-95729-6_4. Epub 2018 Jul 10.
6
PolTree: A Data Structure for Making Efficient Access Decisions in ABAC.
Proc ACM Symp Access Control Model Technol. 2019 Jun;2019:25-35. doi: 10.1145/3322431.3325102.
7
Deploying ABAC policies using RBAC Systems.
J Comput Secur. 2019;27(4):483-506. doi: 10.3233/JCS-191315. Epub 2019 Jul 18.
8
Enabling Attribute-based Access Control in NoSQL Databases.
IEEE Trans Emerg Top Comput. 2023 Jan-Mar;11(1):208-223. doi: 10.1109/tetc.2022.3193577. Epub 2022 Jul 29.
10
Query Monitoring and Analysis for Database Privacy - A Security Automata Model Approach.
Proc Int Conf Web Inf Syst Eng. 2015 Nov;9419:458-472. doi: 10.1007/978-3-319-26187-4_42. Epub 2015 Dec 18.

引用本文的文献

1
A Role-Based Administrative Model for Administration of Heterogeneous Access Control Policies and its Security Analysis.
Inf Syst Front. 2024 Dec;26(6):2255-2272. doi: 10.1007/s10796-021-10167-z. Epub 2021 Jul 21.

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验