Using Attribute Certificates for Role-Based Privilege Management

碩士 === 國立交通大學 === 管理學院碩士在職專班資訊管理組 === 93 === Access control is the function of deciding whether a user is permitted to use or change information contents in information systems. Based on the concept of attribute certificate, Privilege Management Infrastructures (PMI) is a framework for access contro...

Full description

Bibliographic Details
Main Author: 彭玉伃�u
Other Authors: 黃景彰
Format: Others
Language:zh-TW
Online Access:http://ndltd.ncl.edu.tw/handle/30934437311614322840
id ndltd-TW-093NCTU5396064
record_format oai_dc
spelling ndltd-TW-093NCTU53960642015-10-13T11:56:53Z http://ndltd.ncl.edu.tw/handle/30934437311614322840 Using Attribute Certificates for Role-Based Privilege Management 運用屬性憑證於以角色為基礎的授權管理之研究 彭玉伃�u 碩士 國立交通大學 管理學院碩士在職專班資訊管理組 93 Access control is the function of deciding whether a user is permitted to use or change information contents in information systems. Based on the concept of attribute certificate, Privilege Management Infrastructures (PMI) is a framework for access control. Extended from PKI (Public-key Infrastructure), PMI is comparatively new. Role-Based Access Control (RBAC) has been paid much attention in recent years. RBAC reflects the needs for implementing separation of duties and other security policies in organizations. Using a combination of PMI and RBAC, the author of thesis presents a role-based privilege management model. The proposed model works as a framework for practicing PMI. In the proposed model an X-509 attribute certificate does not necessarily include all information for access control. Part of the information is role related. The information about role assignment is either written into an extension field named acceptablePrivilegePolicies or is written into a new extension field. Therefore, user privileges are verified when a user starts a role. Accordingly, the proposed approach broadens applications of the X.509 based attribute certificate. Because XML has been widely considered as a standard for data exchange among various Internet application systems nowadays, this thesis utilizes an XML encoding rule for ASN.1 (XER), to encode an attribute certificate and uses an XML-based language, named XACML, to design a set of RBAC security policies. A verification procedure is also proposed; therefore, the research result of this thesis is ready for real-world applications. 黃景彰 陳安斌 學位論文 ; thesis 85 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立交通大學 === 管理學院碩士在職專班資訊管理組 === 93 === Access control is the function of deciding whether a user is permitted to use or change information contents in information systems. Based on the concept of attribute certificate, Privilege Management Infrastructures (PMI) is a framework for access control. Extended from PKI (Public-key Infrastructure), PMI is comparatively new. Role-Based Access Control (RBAC) has been paid much attention in recent years. RBAC reflects the needs for implementing separation of duties and other security policies in organizations. Using a combination of PMI and RBAC, the author of thesis presents a role-based privilege management model. The proposed model works as a framework for practicing PMI. In the proposed model an X-509 attribute certificate does not necessarily include all information for access control. Part of the information is role related. The information about role assignment is either written into an extension field named acceptablePrivilegePolicies or is written into a new extension field. Therefore, user privileges are verified when a user starts a role. Accordingly, the proposed approach broadens applications of the X.509 based attribute certificate. Because XML has been widely considered as a standard for data exchange among various Internet application systems nowadays, this thesis utilizes an XML encoding rule for ASN.1 (XER), to encode an attribute certificate and uses an XML-based language, named XACML, to design a set of RBAC security policies. A verification procedure is also proposed; therefore, the research result of this thesis is ready for real-world applications.
author2 黃景彰
author_facet 黃景彰
彭玉伃�u
author 彭玉伃�u
spellingShingle 彭玉伃�u
Using Attribute Certificates for Role-Based Privilege Management
author_sort 彭玉伃�u
title Using Attribute Certificates for Role-Based Privilege Management
title_short Using Attribute Certificates for Role-Based Privilege Management
title_full Using Attribute Certificates for Role-Based Privilege Management
title_fullStr Using Attribute Certificates for Role-Based Privilege Management
title_full_unstemmed Using Attribute Certificates for Role-Based Privilege Management
title_sort using attribute certificates for role-based privilege management
url http://ndltd.ncl.edu.tw/handle/30934437311614322840
work_keys_str_mv AT péngyùyúu usingattributecertificatesforrolebasedprivilegemanagement
AT péngyùyúu yùnyòngshǔxìngpíngzhèngyúyǐjiǎosèwèijīchǔdeshòuquánguǎnlǐzhīyánjiū
_version_ 1716850468921016320