网格中安全策略的描述和评估

上传人:小*** 文档编号:252732641 上传时间:2024-11-19 格式:PPT 页数:9 大小:72.50KB
返回 下载 相关 举报
网格中安全策略的描述和评估_第1页
第1页 / 共9页
网格中安全策略的描述和评估_第2页
第2页 / 共9页
网格中安全策略的描述和评估_第3页
第3页 / 共9页
点击查看更多>>
资源描述
Policy language,单击此处编辑母版文本样式,第二级,第三级,第四级,第五级,*,网格中安全策略的描述和评估,陈 昕,2002.3.17,Additional Problems posed by Multiple Administration,Policy integration should incorporate the diverse authorization models that can coexist in a distributed system.,Integrate different sets of policies associated with the domain providing resources,the domain requesting resources and the individual users within each domain.,No single syntax for specification of principals,A generalized way to define applications security requirements,Authorization Framework,Policy language,Generic Authorization and Access-control API,Policy Language,Elements:,access identity,grantor identity,a set of access rights,a set of conditions,Policy language,(continued),Policy language represents a sequence of tokens:,Token type,Defining authority,Value,Extended Access Control Lists(,EACLs,),e.g,Token Type:,access-id-ANYBODY,Token Type:,access-id-GROUP,Defining Authority:,none,Defining Authority:DCE,Value:,none,Value:,15,Token Type:,pos-access-rights,Token Type:,pos-access-rights,Defining Authority:,local-manager,Defining Authority:,local-manager,Value:,FILE:read,Value:,FILE:read FILE:write,Token Type:,authentication-mechanism,Token Type:,location,Defining Authority:,system-manager,Defining Authority:,system-manager,Value:,kerberos,:V5,Value:*.USC.EDU,Extended Access Control Lists,(continued),Credential Evaluation,Extended Access Control Lists,(continued),Identity Credential:,access-id-USER,kerberos,.v5,tomORG.EDU,condition,:time-window pacific-,tzone,6am-7pm,Group membership credential,access-id-GROUP,kerberos,.V5,adminORG.EDU,condition,:privilege:restricted,Delegation credential,grantor,:grantor-id-USER kerberosV5,joeUSTC.EDU.CN,grantee,:,acess,-id-USER kerberosV5,tomUSTC.EDU.CN,objects,:doc.txt,rights,:pos-access-rights local-manager FILE:write,condition,:location local-manager*.,ustc,.,edu,.,cn,GAA-API,GAA-API functions,gaa,-get-object-policy-info,gaa,-check-authorization,gaa,-inquire-object-policy-info,GAA-API Security Context,Identity,Authorization attributes,Evaluation and Retrieval Functions for,Upcalls,
展开阅读全文
相关资源
正为您匹配相似的精品文档
相关搜索

最新文档


当前位置:首页 > 临时分类 > 职业技能


copyright@ 2023-2025  zhuangpeitu.com 装配图网版权所有   联系电话:18123376007

备案号:ICP2024067431-1 川公网安备51140202000466号


本站为文档C2C交易模式,即用户上传的文档直接被用户下载,本站只是中间服务平台,本站所有文档下载所得的收益归上传人(含作者)所有。装配图网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。若文档所含内容侵犯了您的版权或隐私,请立即通知装配图网,我们立即给予删除!