Distributed usage control

被引:118
作者
Pretschner, Alexander [1 ]
Hilty, Manuel [1 ]
Basin, David [1 ]
机构
[1] Swiss Fed Inst Technol, Zurich, Switzerland
关键词
D O I
10.1145/1151030.1151053
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A server-side architecture is used to connect specialized enforcement mechanisms with distributed usage control requirements and policies. The fundamentals of usage control in the notions of provisions, obligations, and compensations in the context of controllability and observability are discussed. The given architecture is compatible with different client-side software enforcement mechanisms including trusted platform technologies and other digital rights management (DRM) mechanisms. Trusted platform technology can be used as a mechanism to control obligations. The high-level policies specifies obligations and provisions that encompasses access control requirement and provisional actions. A compensation management component is used to monitor the obligations to find whether they are violated and thereby necessary actions could be taken for its prevention. The data object is modified in the controllable obligations to enable the trusted systems handle the respective requirements.
引用
收藏
页码:39 / 44
页数:6
相关论文
共 9 条
  • [1] [Anonymous], EXTENSIBLE ACC CONTR
  • [2] Backes M, 2003, LECT NOTES COMPUT SC, V2808, P162
  • [3] Provisions and Obligations in Policy Rule Management
    Claudio Bettini
    Sushil Jajodia
    X. Sean Wang
    Duminda Wijesekera
    [J]. Journal of Network and Systems Management, 2003, 11 (3) : 351 - 372
  • [4] Hilty M, 2005, LECT NOTES COMPUT SC, V3679, P98
  • [5] IANELLI R, OPEN DIGITAL RIGHTS
  • [6] JAJODIA S, 2001, E COMMERCE SECURITY, P133
  • [7] Liu Q., 2003, Conferences in Research and Practice in Information Technology Series, P49
  • [8] Park J., 2004, ACM Transactions on Information and Systems Security, V7, P128, DOI 10.1145/984334.984339
  • [9] SMITH SW, 2005, TRUSTED COMPUTING