首页    期刊浏览 2024年07月18日 星期四
登录注册

文章基本信息

  • 标题:Policy-Engineering Optimization with Visual Representation and Separation-of-Duty Constraints in Attribute-Based Access Control
  • 本地全文:下载
  • 作者:Wei Sun , Hui Su ; Huacheng Xie
  • 期刊名称:Future Internet
  • 电子版ISSN:1999-5903
  • 出版年度:2020
  • 卷号:12
  • 期号:10
  • 页码:164-191
  • DOI:10.3390/fi12100164
  • 出版社:MDPI Publishing
  • 摘要:Recently, attribute-based access control (ABAC) has received increasingly more attention and has emerged as the desired access control mechanism for many organizations because of its flexibility and scalability for authorization management, as well as its security policies, such as separation-of-duty constraints and mutually exclusive constraints. Policy-engineering technology is an effective approach for the construction of ABAC systems. However, most conventional methods lack interpretability, and their constructing processes are complex. Furthermore, they do not consider the separation-of-duty constraints. To address these issues in ABAC, this paper proposes a novel method called policy engineering optimization with visual representation and separation of duty constraints (PEO_VR&SOD). First, to enhance interpretability while mining a minimal set of rules, we use the visual technique with Hamming distance to reduce the policy mining scale and present a policy mining algorithm. Second, to verify whether the separation of duty constraints can be satisfied in a constructed policy engineering system, we use the method of SAT-based model counting to reduce the constraints and construct mutually exclusive constraints to implicitly enforce the given separation of duty constraints. The experiments demonstrate the efficiency and effectiveness of the proposed method and show encouraging results.
  • 关键词:attribute-based access control; policy engineering; visual authorization representation; separation-of-duty constraints attribute-based access control ; policy engineering ; visual authorization representation ; separation-of-duty constraints
国家哲学社会科学文献中心版权所有