Liang-Jui Shen, Yusong Tan, Pian Tao, Pan Dong, Jun Ma
{"title":"为更灵活的特权传播扩展Take-Grant模型","authors":"Liang-Jui Shen, Yusong Tan, Pian Tao, Pan Dong, Jun Ma","doi":"10.1145/3569966.3570088","DOIUrl":null,"url":null,"abstract":"Capability is an important security mechanism in operating systems. The Take-Grant model, as a classic capability system access control model, only has basic rewriting rules to meet the needs of security analysis, but it is difficult to be used for flexible and fine-grained permission propagation. This paper extends the traditional Take-Grant model to control the propagation of capabilities from the direction of propagation, distance and size of propagation, so as to meet the needs of security policies in complex scenarios. Besides, this paper divides permissions to different domains, making the extended model more flexible. The given examples show that the proposed extension to Take-Grant model is more expressive and flexible when doing privilege propagation.","PeriodicalId":145580,"journal":{"name":"Proceedings of the 5th International Conference on Computer Science and Software Engineering","volume":"117 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-10-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Extending Take-Grant Model for More Flexible Privilege Propagation\",\"authors\":\"Liang-Jui Shen, Yusong Tan, Pian Tao, Pan Dong, Jun Ma\",\"doi\":\"10.1145/3569966.3570088\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Capability is an important security mechanism in operating systems. The Take-Grant model, as a classic capability system access control model, only has basic rewriting rules to meet the needs of security analysis, but it is difficult to be used for flexible and fine-grained permission propagation. This paper extends the traditional Take-Grant model to control the propagation of capabilities from the direction of propagation, distance and size of propagation, so as to meet the needs of security policies in complex scenarios. Besides, this paper divides permissions to different domains, making the extended model more flexible. The given examples show that the proposed extension to Take-Grant model is more expressive and flexible when doing privilege propagation.\",\"PeriodicalId\":145580,\"journal\":{\"name\":\"Proceedings of the 5th International Conference on Computer Science and Software Engineering\",\"volume\":\"117 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-10-21\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 5th International Conference on Computer Science and Software Engineering\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3569966.3570088\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 5th International Conference on Computer Science and Software Engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3569966.3570088","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Extending Take-Grant Model for More Flexible Privilege Propagation
Capability is an important security mechanism in operating systems. The Take-Grant model, as a classic capability system access control model, only has basic rewriting rules to meet the needs of security analysis, but it is difficult to be used for flexible and fine-grained permission propagation. This paper extends the traditional Take-Grant model to control the propagation of capabilities from the direction of propagation, distance and size of propagation, so as to meet the needs of security policies in complex scenarios. Besides, this paper divides permissions to different domains, making the extended model more flexible. The given examples show that the proposed extension to Take-Grant model is more expressive and flexible when doing privilege propagation.