An open architecture for secure interworking services

R. Hayton, K. Moody
{"title":"An open architecture for secure interworking services","authors":"R. Hayton, K. Moody","doi":"10.1109/ICDCS.1997.598061","DOIUrl":null,"url":null,"abstract":"There is a developing need for applications and distributed services to cooperate or interoperate. The article describes an architectural approach to security. The key idea is that a process is the universal client entity; a process may act on behalf of an identified individual as in traditional security schemes. More generally, a process may adopt an application specific name or role, and this is used as the basis for authentication in Oasis. A service may then be written in terms of service specific categories of clients, decoupled from the mechanisms used to specify and enforce access control policy. This approach allows great flexibility when integrating a number of services, and reduces the mismatch of policies that is common in heterogeneous systems. In addition, Oasis services may be integrated with alternative authentication and access control schemes, providing a truly open architecture. A flexible security definition is meaningless if not backed by a robust and efficient implementation. Oasis has been fully implemented, and is inherently distributed and scalable. We describe the general approach, then concentrate on revocation, where security designs are most often criticised. Oasis is unique in supporting the rapid and selective revocation of privileges which can cascade between services and organisations.","PeriodicalId":122990,"journal":{"name":"Proceedings of 17th International Conference on Distributed Computing Systems","volume":"42 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1996-09-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"23","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of 17th International Conference on Distributed Computing Systems","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICDCS.1997.598061","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 23

Abstract

There is a developing need for applications and distributed services to cooperate or interoperate. The article describes an architectural approach to security. The key idea is that a process is the universal client entity; a process may act on behalf of an identified individual as in traditional security schemes. More generally, a process may adopt an application specific name or role, and this is used as the basis for authentication in Oasis. A service may then be written in terms of service specific categories of clients, decoupled from the mechanisms used to specify and enforce access control policy. This approach allows great flexibility when integrating a number of services, and reduces the mismatch of policies that is common in heterogeneous systems. In addition, Oasis services may be integrated with alternative authentication and access control schemes, providing a truly open architecture. A flexible security definition is meaningless if not backed by a robust and efficient implementation. Oasis has been fully implemented, and is inherently distributed and scalable. We describe the general approach, then concentrate on revocation, where security designs are most often criticised. Oasis is unique in supporting the rapid and selective revocation of privileges which can cascade between services and organisations.
用于安全互通服务的开放体系结构
对应用程序和分布式服务进行合作或互操作的需求正在不断发展。本文描述了一种实现安全性的体系结构方法。关键思想是,流程是通用的客户实体;在传统的安全方案中,进程可以代表已识别的个人。更一般地说,进程可以采用特定于应用程序的名称或角色,这在Oasis中用作身份验证的基础。然后可以根据服务特定的客户端类别编写服务,与用于指定和实施访问控制策略的机制解耦。这种方法在集成大量服务时具有很大的灵活性,并减少了异构系统中常见的策略不匹配。此外,Oasis服务可以与可选的身份验证和访问控制方案集成,从而提供真正开放的体系结构。如果没有健壮和高效的实现支持,灵活的安全定义是没有意义的。Oasis已经完全实现,并且本质上是分布式和可伸缩的。我们描述了一般的方法,然后专注于撤销,安全设计最常受到批评。Oasis在支持可以在服务和组织之间级联的特权的快速和选择性撤销方面是独一无二的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信