返回
Applying a usage control model in an operating system kernel
DOI:10.1016/j.jnca.2011.03.019.png)
摘要
En 中文
Operating systems traditionally use access control mechanisms to manage access to system resources like files, network connections, and memory areas. However, classic access control models are not suitable for regulating access to the diversity of ways data is available and used today. Modern usage control models go beyond traditional access control, addressing its limitations related to attribute mutability and continuous usage permission validation. The recently proposed UCONABC model establishes a predicate-based framework to satisfy the new access/usage control needs in computing systems. This paper defines a usage control model based on UCONABC and describes a framework to implement it in an operating system kernel, on top of the existing DAC mechanism. A language for representing usage control entities and rules is also proposed, and some typical access/usage control scenarios are represented using it, to show its usefulness. Finally, a prototype of the proposed framework was built in an operating system kernel, to control the usage of local files. The prototype evaluation shows that the proposed model is feasible, straightforward, and may serve as a basis for more complex usage control frameworks. (C) 2011 Elsevier Ltd. All rights reserved.
Keyword:
Access control
Usage control
Kernel services
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
8
论文数:
3.6K
被引数:
1.1W
机构
引用论文
Crystal structures of thiocyanate polyamine copper(II) complexes. Part II. Bis-(1,3-diaminopropane)isothiocyanatocopper(II) perchlorate硫氰酸盐多胺铜 (II) 配合物的晶体结构。第二部分。双-(1,3-二氨基丙烷) 异硫氰酸盐 (II) 高氯酸盐
没有更多内容

