以权宜之计为中心的集团内部合作的晶格解释

K. Bijon, Tahmina Ahmed, R. Sandhu, R. Krishnan
{"title":"以权宜之计为中心的集团内部合作的晶格解释","authors":"K. Bijon, Tahmina Ahmed, R. Sandhu, R. Krishnan","doi":"10.4108/ICST.COLLABORATECOM.2012.250468","DOIUrl":null,"url":null,"abstract":"For various reasons organizations need to collaborate with external consultants, e.g. domain specialists, on specific projects. Many security-oriented organizations deploy multi-level systems which enforce one directional information flow in a lattice of security labels. However, traditional lattice constructions are not suitable for accommodating external consultants, since such consultants are not “true insiders” but rather “expedient insiders” who should receive much more limited privileges than employees. An authorization model for group-centric collaboration with expedient insiders (GEI) has been recently proposed, wherein organizations create groups and replicate the organizational lattice with selected content for such collaborations [4]. Motivated by GEI, in this paper, we formulate a novel lattice construction wherein a new collaboration category is introduced for each new collaboration group, in a manner significantly different from the usual process of defining new security categories in a lattice. In particular, a collaboration category brings together only the required objects and users. We develop a formal model for lattices with collaborative compartments (LCC) comprising administrative and operational parts covering the life-cycle of such collaborations. We formally prove the equivalence of LCC and GEI, thereby precisely characterizing the information flow and security properties of GEI which heretofore had only been informally considered. This equivalence shows that GEI can be realized via LBAC with minimal operational disruptions.","PeriodicalId":225191,"journal":{"name":"8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom)","volume":"80 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-10-14","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"A lattice interpretation of group-centric collaboration with expedient insiders\",\"authors\":\"K. Bijon, Tahmina Ahmed, R. Sandhu, R. Krishnan\",\"doi\":\"10.4108/ICST.COLLABORATECOM.2012.250468\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"For various reasons organizations need to collaborate with external consultants, e.g. domain specialists, on specific projects. Many security-oriented organizations deploy multi-level systems which enforce one directional information flow in a lattice of security labels. However, traditional lattice constructions are not suitable for accommodating external consultants, since such consultants are not “true insiders” but rather “expedient insiders” who should receive much more limited privileges than employees. An authorization model for group-centric collaboration with expedient insiders (GEI) has been recently proposed, wherein organizations create groups and replicate the organizational lattice with selected content for such collaborations [4]. Motivated by GEI, in this paper, we formulate a novel lattice construction wherein a new collaboration category is introduced for each new collaboration group, in a manner significantly different from the usual process of defining new security categories in a lattice. In particular, a collaboration category brings together only the required objects and users. We develop a formal model for lattices with collaborative compartments (LCC) comprising administrative and operational parts covering the life-cycle of such collaborations. We formally prove the equivalence of LCC and GEI, thereby precisely characterizing the information flow and security properties of GEI which heretofore had only been informally considered. This equivalence shows that GEI can be realized via LBAC with minimal operational disruptions.\",\"PeriodicalId\":225191,\"journal\":{\"name\":\"8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom)\",\"volume\":\"80 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2012-10-14\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.4108/ICST.COLLABORATECOM.2012.250468\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"8th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4108/ICST.COLLABORATECOM.2012.250468","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

由于各种原因,组织需要在特定项目上与外部顾问(例如领域专家)合作。许多面向安全的组织部署多级系统,这些系统在安全标签格中强制执行单向信息流。然而,传统的格子结构并不适合容纳外部顾问,因为这些顾问不是“真正的内部人士”,而是“权宜之计的内部人士”,他们应该获得比员工更有限的特权。最近提出了一种以权宜内部人(expedient insiders, GEI)为中心的以群体为中心的协作的授权模型,其中组织创建群体,并为这种协作复制带有选定内容的组织格[4]。在GEI的激励下,本文提出了一种新的格结构,其中每个新的协作组引入一个新的协作类别,其方式与通常在格中定义新的安全类别的过程有很大的不同。特别地,协作类别只汇集了所需的对象和用户。我们开发了一个具有协作隔间(LCC)的格子的正式模型,其中包括涵盖此类协作生命周期的管理和操作部分。我们正式证明了LCC和GEI的等价性,从而精确地表征了迄今为止仅被非正式考虑的GEI的信息流和安全特性。这一等价性表明,通过LBAC可以实现GEI,且操作中断最小。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A lattice interpretation of group-centric collaboration with expedient insiders
For various reasons organizations need to collaborate with external consultants, e.g. domain specialists, on specific projects. Many security-oriented organizations deploy multi-level systems which enforce one directional information flow in a lattice of security labels. However, traditional lattice constructions are not suitable for accommodating external consultants, since such consultants are not “true insiders” but rather “expedient insiders” who should receive much more limited privileges than employees. An authorization model for group-centric collaboration with expedient insiders (GEI) has been recently proposed, wherein organizations create groups and replicate the organizational lattice with selected content for such collaborations [4]. Motivated by GEI, in this paper, we formulate a novel lattice construction wherein a new collaboration category is introduced for each new collaboration group, in a manner significantly different from the usual process of defining new security categories in a lattice. In particular, a collaboration category brings together only the required objects and users. We develop a formal model for lattices with collaborative compartments (LCC) comprising administrative and operational parts covering the life-cycle of such collaborations. We formally prove the equivalence of LCC and GEI, thereby precisely characterizing the information flow and security properties of GEI which heretofore had only been informally considered. This equivalence shows that GEI can be realized via LBAC with minimal operational disruptions.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信