通过智能证书实现Web上的RBAC

Joon S. Park, R. Sandhu
{"title":"通过智能证书实现Web上的RBAC","authors":"Joon S. Park, R. Sandhu","doi":"10.1145/319171.319172","DOIUrl":null,"url":null,"abstract":"We have described in another paper how to develop and use smart certi cates by extending X.509 with several sophisticated features for secure attribute services on the Web. In this paper, we describe an implementation of RBAC (Role-Based Access Control) with role hierarchies on the Web as one possible application of smart certi cates. To support RBAC, we issued smart certi cates which hold the subjects' role information and con gured a Web server to use the role information in the certi cate instead of identities for its access control mechanism. Since the subjects' role information is provided integrity, the Web server can trust the role information after authentication and certi cate veri cation by SSL, and uses it for role-based access control. To maintain compatibility with existing technologies, such as SSL, we used a bundled (containing the subject's identity and role information) smart certi cate in the user-pull model.","PeriodicalId":355233,"journal":{"name":"ACM Workshop on Role-Based Access Control","volume":"27 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1999-10-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"61","resultStr":"{\"title\":\"RBAC on the Web by smart certificates\",\"authors\":\"Joon S. Park, R. Sandhu\",\"doi\":\"10.1145/319171.319172\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"We have described in another paper how to develop and use smart certi cates by extending X.509 with several sophisticated features for secure attribute services on the Web. In this paper, we describe an implementation of RBAC (Role-Based Access Control) with role hierarchies on the Web as one possible application of smart certi cates. To support RBAC, we issued smart certi cates which hold the subjects' role information and con gured a Web server to use the role information in the certi cate instead of identities for its access control mechanism. Since the subjects' role information is provided integrity, the Web server can trust the role information after authentication and certi cate veri cation by SSL, and uses it for role-based access control. To maintain compatibility with existing technologies, such as SSL, we used a bundled (containing the subject's identity and role information) smart certi cate in the user-pull model.\",\"PeriodicalId\":355233,\"journal\":{\"name\":\"ACM Workshop on Role-Based Access Control\",\"volume\":\"27 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1999-10-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"61\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"ACM Workshop on Role-Based Access Control\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/319171.319172\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACM Workshop on Role-Based Access Control","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/319171.319172","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 61

摘要

我们已经在另一篇论文中描述了如何通过为Web上的安全属性服务扩展带有几个复杂特性的X.509来开发和使用智能证书。在本文中,我们描述了基于角色的访问控制(RBAC)在Web上的角色层次结构的实现,作为智能证书的一种可能的应用。为了支持RBAC,我们颁发了包含主体角色信息的智能证书,并使Web服务器在其访问控制机制中使用证书中的角色信息而不是身份信息。由于主体的角色信息是完整提供的,因此Web服务器可以通过SSL进行身份验证和证书验证后信任角色信息,并将其用于基于角色的访问控制。为了保持与现有技术(如SSL)的兼容性,我们在用户拉模型中使用了捆绑的(包含主体的身份和角色信息)智能证书。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
RBAC on the Web by smart certificates
We have described in another paper how to develop and use smart certi cates by extending X.509 with several sophisticated features for secure attribute services on the Web. In this paper, we describe an implementation of RBAC (Role-Based Access Control) with role hierarchies on the Web as one possible application of smart certi cates. To support RBAC, we issued smart certi cates which hold the subjects' role information and con gured a Web server to use the role information in the certi cate instead of identities for its access control mechanism. Since the subjects' role information is provided integrity, the Web server can trust the role information after authentication and certi cate veri cation by SSL, and uses it for role-based access control. To maintain compatibility with existing technologies, such as SSL, we used a bundled (containing the subject's identity and role information) smart certi cate in the user-pull model.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信