手机版

A Framework for Role-Based Access Control in Group Communica(2)

时间:2025-07-04   来源:未知    
字号:

In this paper we analyze the requirements access control mechanisms must fulfill in the context of group communication and define a framework for supporting fine-grained access control in client-server group communication systems. Our framework combines ro

applicationtode neitsspeci cpolicieswhiletheenforcementisperformedinane cientmannerbytheGCS.Thisisachievedbyde ningasetofbasicgroupoperationsandrolesthatcanbecon-trolledandenforcedbytheGCS.Anyapplicationspeci cpolicycanbedecomposedintotheseba-sicoperationsandapplicationspeci crolescanbemappedtosystemroles.

Weanalyzewhataretheimplicationsofprocess(serversandclients)failuresandnetworkconnec-tivitychangesonthelifecycleofagrouppol-icyingeneral,andofanaccesscontrolpolicyinparticular,andsuggesthowtheseissuescanbeaddressed.RoadmapWediscussthefailureandtrustmodelsweuseinSection2.InSection3wepresentindetailsthecomponentsforagrouppolicy,whileinSection4wediscussthee ectsofprocessfailuresandnetworkpartitionsonthelifecycleofthepolicy.WeoverviewrelatedworkinSection5.Finally,wesummarizeourworkandsuggestfutureworkdirectionsinSection6.

2TrustandFailureModels

Inthissection,wediscussthetrustandfailuremod-elsweareusinginthispaper.

2.1TrustModel

Inclient-serverGCS,atrustmodelhastode nethetrustrelationshipswithineachlayer(trustrelationshipbetweenclientsandtrustrelationshipbetweenservers)aswellasbetweenlayers(i.e.doclientstrustserversornot).Giventhisenvironment,severaltrustmodelsarepossible,rangingfromamodelwherenoentitytrustsanyotherentityforanyoperation,bothwithinalayerandbetweenlayers,toanoptimisticmodelwhereserversandclientstrusteachothercompletely.Inthispaper,weadoptthefollowingtrustmodel: Serverstrusteachother:Inorderforthesystemtobebootstrappedcorrectly,alistoflegitimateserversshouldbeprovidedtoallservers,intheformofanACL.Settingupthislistisasystemadministrator’staskandnotanapplicationtask.Weassumethatthereisawaytoauthenticateaserverwhenitcomesupandverifywhetheritisontheauthorizedcon gurationlist.Onceauthenti-catedandauthorizedallserverstrusteachother.Wenotethatingeneralthenumberofserversissmallandthatthewaythesesystemsareusedis

rstde neaservers’con gurationthatprovidesbestperformanceforaspeci cnetworkenviron-mentandapplicationdeployment.Therefore,inthiscase,anACLisanacceptablesolution. Clientstrustserverstoenforcetheaccesscontrolpolicy.Thisassumptionisacceptablebecause,intheclient-serverGCSarchitecture,clientsal-readytrusttheserverstomaintaingroupmem-bershipandtotransport,orderanddelivergroupmessages,soitseemsnaturaltotrustthemalsoforenforcingtheaccesscontrolpolicy.Further-more,thiswillallowforamoree cientenforce-mentsinceinnumerouscasesthedecisioncanbemadebyeachserverlocally,diminishingthecom-municationoverhead. Clientsarenottrusted(eitherbytheotherclientsorbyservers).Therefore,compromisingoneclientdoesnotcompromisethesecurityofthewholesystem.

2.2FailureModel

Ourmodelconsidersadistributedsystemthatiscomposedofagroupofserversexecutingonseveralcomputersandcoordinatingtheiractionsbyexchang-ingmessages.Themessageexchangeisconductedviaasynchronousmulticastandunicast.Messagescanbelostorcorrupted.Weassumethatmessagecorrup-tionismaskedbyalowerlayer.Aclientobtainsthegroupcommunicationservicesbyconnectingtooneoftheservers.Aclientcanconnectlocallyorremotely.Bothclientsandserversmayfail.Whenaserverfails,alltheclientsthatareconnectedtothatserverwillstopreceivinggroupcommunicationservices;theyarenotredirectedtootherservers.

Duetonetworkevents(e.g.,congestionoroutrightfailures)thenetworkcanbesplitintodisconnectedsubnetworkfragments.Atthegroupcommunicationlayer,thisisreferredtoasapartition.Anetworkpar-titionsplitstheserversandcanpotentiallysplitsev-eralclientgroupsindi erentcomponents.Whilepro-cesses(serversorclients)areinseparatedisconnectedcomponentstheycannotexchangemessages.Whenanetworkpartitionisrepaired,thedisconnectedcompo-nentsmergeintoalargerconnectedcomponent,thisisreferredatthegroupcommunicationlayerasamerge.Firstserversaremerged,whichinturncantriggerseveralclientgroupstobemerged.

Byzantine(arbitrary)processfailuresarenotcon-sideredinthiswork.

…… 此处隐藏:2053字,全部文档内容请下载后查看。喜欢就下载吧 ……
A Framework for Role-Based Access Control in Group Communica(2).doc 将本文的Word文档下载到电脑,方便复制、编辑、收藏和打印
×
二维码
× 游客快捷下载通道(下载后可以自由复制和排版)
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
VIP包月下载
特价:29 元/月 原价:99元
低至 0.3 元/份 每月下载150
全站内容免费自由复制
注:下载文档有可能出现无法下载或内容有问题,请联系客服协助您处理。
× 常见问题(客服时间:周一到周五 9:30-18:00)