Efficient Policy Checking across Administrative Domains

David Evans, D. Eyers
{"title":"Efficient Policy Checking across Administrative Domains","authors":"David Evans, D. Eyers","doi":"10.1109/POLICY.2010.36","DOIUrl":null,"url":null,"abstract":"Information flow control provides formal techniques for specifying policies that dictate what data may flow where, and for ensuring compliance with those policies. In event-based systems, this amounts to deciding whether a particular event should be delivered to a recipient and what parts of that event the recipient should be allowed to see. This is usually effected through labels that identify the privileges required for access to, and the integrity of, parts of events. Within an organisation, agreement on the meanings of these labels can be reached by flat. However, when multiple organisations are involved, interpretation of these labels is tied up with the data usage agreements defining how the organisations interact. We provide a means to link inter- and intra-organisation information flow control, using the same mechanism for each when checking policy compliance. Event producers are insulated from concerns about whether event receivers are within their organisation or outside it.","PeriodicalId":143330,"journal":{"name":"2010 IEEE International Symposium on Policies for Distributed Systems and Networks","volume":"37 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2010-07-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2010 IEEE International Symposium on Policies for Distributed Systems and Networks","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/POLICY.2010.36","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Information flow control provides formal techniques for specifying policies that dictate what data may flow where, and for ensuring compliance with those policies. In event-based systems, this amounts to deciding whether a particular event should be delivered to a recipient and what parts of that event the recipient should be allowed to see. This is usually effected through labels that identify the privileges required for access to, and the integrity of, parts of events. Within an organisation, agreement on the meanings of these labels can be reached by flat. However, when multiple organisations are involved, interpretation of these labels is tied up with the data usage agreements defining how the organisations interact. We provide a means to link inter- and intra-organisation information flow control, using the same mechanism for each when checking policy compliance. Event producers are insulated from concerns about whether event receivers are within their organisation or outside it.
跨管理域的高效策略检查
信息流控制提供了正式的技术,用于指定规定哪些数据可以流向何处的策略,并确保遵守这些策略。在基于事件的系统中,这相当于决定是否应该将特定事件传递给接收者,以及应该允许接收者查看该事件的哪些部分。这通常是通过标识访问事件部分所需的特权和完整性的标签来实现的。在一个组织内,对这些标签的含义达成一致可以通过平面。然而,当涉及多个组织时,这些标签的解释与定义组织如何交互的数据使用协议联系在一起。我们提供了一种连接组织内部和内部信息流控制的方法,在检查政策遵从性时对每个信息流控制使用相同的机制。事件生产者与事件接收者是在其组织内部还是外部的问题无关。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信