【正文】
魯劍鋒 2020年 3月 2日 星期一 職責(zé)分離 SoD: Separation of duty 安全策略約束之 內(nèi)容 1. SoD簡介 2. SoD分類 3. SoD執(zhí)行方法 4. 研究展望 SoD簡介 ? The concept of SoD has long existed in the physical world, sometimes under the name “the twoman rule”, for example, in the banking industry and the military. ? 1975: In the information security literature the notion of SoD first appeared in Saltzer and Schroeder under the name “separationof privilege”. ? 1992: In one of the earliest papers on RBAC, Ferraiolo and Kuhn used the terms static and dynamic SoD to refer to static and dynamic enforcement of SoD. ? 1995: Ferraiolo et al. defined static SoD as: “A user is authorized as a member of a role only if that role is not mutually exclusive with any of the other roles for which the user already possesses membership.” SoD簡介 ① ssod definition ② smer definition SoD簡介 ? The dangers with equating SMER constraints with SoD policies is ① A danger with equating SMER constraints with SoD policies is that the SMER constraints may be specified without a clear specification of what ob