WO2000051288A2 - Modification de la recommandation x.741 de l'uit-t pour une protection d'acces unitaire a des objets geres et a des fichiers de donnees - Google Patents

Modification de la recommandation x.741 de l'uit-t pour une protection d'acces unitaire a des objets geres et a des fichiers de donnees Download PDF

Info

Publication number
WO2000051288A2
WO2000051288A2 PCT/DE2000/000517 DE0000517W WO0051288A2 WO 2000051288 A2 WO2000051288 A2 WO 2000051288A2 DE 0000517 W DE0000517 W DE 0000517W WO 0051288 A2 WO0051288 A2 WO 0051288A2
Authority
WO
WIPO (PCT)
Prior art keywords
managed objects
recommendation
file
access
attribute
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/DE2000/000517
Other languages
German (de)
English (en)
Other versions
WO2000051288A3 (fr
Inventor
Herwig Kittl
Maria Lauer
Klaus-Dieter Müller
Bernhard Nauer
Josef Glösmann
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Siemens AG
Siemens Corp
Original Assignee
Siemens AG
Siemens Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Siemens AG, Siemens Corp filed Critical Siemens AG
Priority to DE10080454T priority Critical patent/DE10080454D2/de
Publication of WO2000051288A2 publication Critical patent/WO2000051288A2/fr
Publication of WO2000051288A3 publication Critical patent/WO2000051288A3/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • G06F21/6236Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database between heterogeneous systems
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/04Network management architectures or arrangements
    • H04L41/052Network management architectures or arrangements using standardised network management architectures, e.g. telecommunication management network [TMN] or unified network management architecture [UNMA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/28Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2141Access rights, e.g. capability lists, access control lists, access tables, access matrices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2145Inheriting rights or properties, e.g., propagation of permissions or restrictions within a hierarchy
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords

Definitions

  • the ITU-T (International Telecommunication Union, Telecommunications Standardization Sector) recommendation X.741 is currently only intended for access protection of managed objects.
  • the subject matter of the application relates to a method for realizing uniform access protection to managed objects and files based on ITU-T recommendation X.741, comprising the features of the preamble of claim 1, 4 or 5.
  • ITU-T recommendation M.3010 describes the architecture and interfaces of a Telecommunication Management Network TMN.
  • the interface between operations systems and network elements is designated Q 3 , that between the operations systems is designated X.
  • CMIP Common Management Information Protocol
  • ITU-T rec X.710 / X.711 was developed and managed objects were introduced, in which the management information is stored .
  • the managed objects are administered with CMIP.
  • the managed objects are processed in accordance with the ITU-T rec. X.720 to X.722 described with GDMO (Guidelines for the Definition of Managed Objects). In practice, this implementation of the Q 3 and X interfaces is not sufficient.
  • mass data e.g.
  • ITU-T rec. X.741 interprets and applies the model described in ITU-T X.812 for access control to management applications that use CMIP as the management protocol. It defines an object model with which access rights can be managed at the object class, object instance, attribute and attribute value level. A direct application of the ITU-T rec. X.741 on file access is not possible.
  • the subject of the registration is based on the problem described in ITU-T rec. Adapt the object model described in X.741 so that it can be used uniformly both for access protection for managed objects and for access protection for files.
  • the subject of the application makes use of the knowledge that the ITU-T rec. X.741 described schemes (access control list schemes, label based schemes, context based schemes or capacity based schemes) for an access control to which managed objects can be transferred to a file access control.
  • the subject of registration is ITU-T rec. X.741 in such a way that it is used to protect files accessed by file trans- fer (e.g. with FTAM or FTP) is made usable.
  • Access protection to managed object classes and files is implemented in a uniform form, which means that an operator for access protection offers uniform handling (look and feel) and uniform management. Synergy effects can be achieved when implementing uniform access protection.
  • the file access protection provided by the subject of the application is independent of the file management system and of the access method. It can be used, for example, for FTAM (ISO 8571) and for FTP (RFC (Request for Comments) 959 and 1123).
  • the object of registration can be executed as a separate model for file protection.
  • FIG. 1 shows a basic illustration of the general relationship of a telecommunications management network to a telecommunications network
  • FIG. 2 shows an exemplary embodiment for the simplified physical architecture of a telecommunications management network ⁇ and FIG. 3 relationships in an object model.
  • ITU-T rec. M.3010 describes the architecture and the interface ⁇ provide a Telecommunications Management Network TMN.
  • the interface between the operations systems and network elements is designated by Q, that between the operations systems by X.
  • a Data Communication Network DCN consists of several operating systems OS, a workstation WS, another telecommunications management network oTMN (for: other telecommunications management network) and several switching devices EX (for: Exchange) and several transmission devices TR (for: Transmission) connected.
  • the switching devices EX and the transmission devices TR which are alternately connected to one another, belong to the telecommunications network TN.
  • a data processing device TEPC for: telecommunication terminal personal computer
  • a telephone device TEF for: telecommunication terminal telephone
  • the data communication network DCN is via an interface X, an interface F or an interface Q 3 ⁇ it with one or more operating systems OS, via an interface F with one or more workstations WS, via an interface Q 3 or an interface F to one or more devices MD (for: mediation device), via an interface Q 3 to one or more network elements NE, via an interface Q 3 to one or more QA and can be connected via an interface X to another telecommunication management network (not shown).
  • the device MD is connected to one or more devices QA via an interface Q x (for: Q adapter) and an interface Q x connected to one or more network elements NE.
  • the ITU-T rec. Schemes described in X.741 access control list schemes, label based schemes, context based schemes or capacity based schemes) for access control to the managed objects are transferred to a file access control according to the application.
  • the in the object model of the ITU-T rec. X.741 described CMIP operations to which file accesses are adapted. These adjustments are essentially based on an expansion of the behavior, an expansion of the attribute syntax and the definition of new attributes and actions. The following changes are made:
  • Access control rules object class defaultAccess attribute the attribute syntax is extended to the file access methods such as “create”, “delete”, “read”, “write”, “readAttributes”, “execute”, “noOperation” ... deni- alGranularity Attribute: the attribute syntax is expanded to include values that relate to the granularity of the file access, such as “fileOperation” and "singleFile”. The behavior of the attribute is adjusted accordingly.
  • Behavior The behavior is expanded by the following sentence: "If the targets list attribute identifies files, then the initiators list attribute must identify initiators in the context of a file access scheme.”
  • Behavior should be expanded to "managed objects or files”.
  • the object class is expanded by attributes for file selection (such as fileType, fileName) and by optional attributes in which conditions for file selection can be formulated (such as fileFilter, fi lePatternList to identify file names according to a defined pattern).
  • OperationsListPackage operationsList attribute: the attribute syntax refers to the ASN.l (Abstract Syntax Notation No 1) type "operationType". This type is extended by values for file access methods such as "create”, “delete”, “read”, “write”, “readAttributes”, “execute”, “noOperation” ... An access protection password can be optionally defined for each method . The behavior of the attribute is adjusted accordingly.
  • the package should be extended by the actions "resetPassword” (resetting an access protection password to a predefined value) and “cancelPassword” (removing an access protection password).
  • An access protection password can be optionally defined for each method. The behavior of the attribute is adjusted accordingly.
  • the actions “resetPassword” (resetting an access protection password to a predefined value) and “cancelPassword” (removing an access protection password) should be added.
  • Capability initiators object class capabilityldentitiesList Attribute the attribute syntax refers to the ASN.l type "operationType". This type is extended by values for file access methods such as “create”, “delete”, “read”, “write”, “readAttributes”, “execute”, “no ⁇ Operation” ... An access protection password can be optionally defined for each method. The behavior of the attribute is adjusted accordingly.
  • Object model The previously used in the ITU-T rec.
  • the X.741 defined object model remains unchanged and is extended allomorphically by the subclasses required for file access protection.
  • the allomorphic extension of the object model is understood to mean that an object model derived from a given object model is handled as an instance of an object model.
  • the aim of this type of implementation is to define and reuse already defined object classes that can still be used for file access protection.
  • 3 shows the example of relationships in an object model in which an object class access control AC (for: accessControl) in the course of inheritance IH (for: inheritance) an object class access control scheme ACR (for: accessControlRules) and an object class file- Access control scheme FACR (for: fileAccessControlRules) can be formed.
  • AC for: accessControl
  • ACR object class access control scheme
  • FACR object class file- Access control scheme

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • Bioethics (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Databases & Information Systems (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
  • Storage Device Security (AREA)

Abstract

La recommandation X.741 de l'UIT-T prévue depuis longtemps seulement pour la protection d'accès à des objets gérés est modifiée de telle sorte qu'elle soit également adaptée à une protection d'accès à des fichiers de données, ce qui offre une protection d'accès unitaire avec une manipulation unitaire et une gestion unitaire. Des formes d'exécutions particulières de l'objet de la demande sont données par adjonction, en complément, au modèle d'objet existant pour une protection d'accès à des objets gérés, d'un autre modèle d'objet pour une protection d'accès à des fichiers de données, par élargissement du modèle d'objet existant pour une protection d'accès à des objets gérés avec des sous-classes pour une protection d'accès à des fichiers de données et par élargissement du modèle d'objet existant pour le transformer en un nouveau modèle d'objet pour objets gérés et fichiers de données. L'objet de la demande peut être réalisé sous la forme d'un modèle autonome pour la protection de fichiers de données.
PCT/DE2000/000517 1999-02-26 2000-02-24 Modification de la recommandation x.741 de l'uit-t pour une protection d'acces unitaire a des objets geres et a des fichiers de donnees Ceased WO2000051288A2 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
DE10080454T DE10080454D2 (de) 1999-02-26 2000-02-24 Modifizierung der ITU-T recommendation X.741 für einen einheitlichen Zugriffsschutz auf Managed Objects und Dateien

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
DE19908429.7 1999-02-26
DE19908429 1999-02-26

Publications (2)

Publication Number Publication Date
WO2000051288A2 true WO2000051288A2 (fr) 2000-08-31
WO2000051288A3 WO2000051288A3 (fr) 2000-12-21

Family

ID=7899015

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/DE2000/000517 Ceased WO2000051288A2 (fr) 1999-02-26 2000-02-24 Modification de la recommandation x.741 de l'uit-t pour une protection d'acces unitaire a des objets geres et a des fichiers de donnees

Country Status (2)

Country Link
DE (1) DE10080454D2 (fr)
WO (1) WO2000051288A2 (fr)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE10146361B4 (de) * 2001-09-20 2007-02-01 Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V. Verteiltes System
JP2008029094A (ja) * 2006-07-20 2008-02-07 Hitachi Ltd 電力変換装置
JP2017131061A (ja) * 2016-01-21 2017-07-27 ヤンマー株式会社 電力変換装置及びその組み立て方法

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
"ITU-T Recommendation X.741 Corrigendum 1" ITU-T INTERNATIONAL TELECOMMUNICATION UNION, 1. Oktober 1996 (1996-10-01), Seiten 1-123, XP002144722 in der Anmeldung erw{hnt *
"X.741 Recommendation" ITU-T INTERNATIONAL TELECOMMUNICATION UNION, 1. April 1995 (1995-04-01), Seiten 1-1-123, XP002144721 in der Anmeldung erw{hnt *
NETWORK WORKING GROUP: "RFC 959 - FTP - File Transfer Protocol" INTERNET RFCS, 1. Oktober 1985 (1985-10-01), XP002144723 in der Anmeldung erw{hnt *
START K ET AL: "The distribution management of service software" COMPUTER STANDARDS AND INTERFACES,CH,ELSEVIER SEQUOIA. LAUSANNE, Bd. 17, Nr. 3, 1. Juni 1995 (1995-06-01), Seiten 291-301, XP004008584 ISSN: 0920-5489 *

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE10146361B4 (de) * 2001-09-20 2007-02-01 Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V. Verteiltes System
JP2008029094A (ja) * 2006-07-20 2008-02-07 Hitachi Ltd 電力変換装置
US7751201B2 (en) 2006-07-20 2010-07-06 Hitachi, Ltd. Power converter
JP2017131061A (ja) * 2016-01-21 2017-07-27 ヤンマー株式会社 電力変換装置及びその組み立て方法

Also Published As

Publication number Publication date
DE10080454D2 (de) 2001-07-26
WO2000051288A3 (fr) 2000-12-21

Similar Documents

Publication Publication Date Title
DE69319103T2 (de) Netzwerkverwaltungssystem
DE69529846T2 (de) Verfahren zum vergleich von attributwerten von steuerbaren objektausdrücken in einem netzwerkelement
DE69333960T2 (de) Namenauflösung in einem Mehrsystem-Netz
DE69510226T2 (de) Verfahren und vorrichtung zur aktualisierung oder änderung eines netzwerkverzeichnisses
DE69738309T2 (de) Verteilte verarbeitung
DE69832946T2 (de) Verteiltes System und Verfahren zur Steuerung des Zugriffs auf Netzmittel und Ereignismeldungen
DE69424597T2 (de) Erweiterbares Dateiensystem
DE69726853T2 (de) System und verfahren zum totalen kommissionieren von telekommunikationsdiensten
DE69425093T2 (de) Verfahren zum Erzeugen einer Gruppe erweiterbarer Zusatzdienste für Objekte in einem objektoriertierten System
EP0959588A2 (fr) Elément de réseau avec le dispositif de commande et la méthode de contrÔle
EP0520083B1 (fr) Protection de la consistance des données dans un système de télécommunications numériques
DE69634650T2 (de) Telekommunikationsdienstwechselwirkungen
EP0825524A1 (fr) Procédé pour nommer des objets
DE3782349T3 (de) Netzwerk-Ereignisseidentifikationseinrichtungen.
DE69427198T2 (de) Kommunikationssystem mit einem ein verwaltungsmodul einschliessendem netz
DE10115722A1 (de) Effiziente Echtzeitverwaltung von Speicherbetriebsmitteln
DE69833845T2 (de) Intelligente Schnittstelle zwischen einem Dienststeuerpunkt und einem Signalisierungsnetz
EP0557566B1 (fr) Méthode d'accès par mot de passe administré hiérarchiquement aux indications d'accès d'utilisateur dans une base de données d'un central à commande programmée
DE10110039A1 (de) Ein Verfahren zur generischen Beschreibung und Manipulation beliebiger Datenstrukturen
DE19930119C2 (de) Prioritätsverwaltungsverfahren
EP0850545A1 (fr) Systeme environnemental operationnel pour des applications de services d'un reseau de telecommunication
DE19534207A1 (de) Verfahren zur Kodierung oder Dekodierung von Protokolldateneinheiten (PDU)
EP0614551B1 (fr) Procede de commande de l'interaction entre une interface utilisateur et une application
EP1157566A1 (fr) Procede et element de reseau pour exploiter un reseau de telecommunication
DE19922853A1 (de) Verfahren zur Ausführung einer Anforderung einer Netzwerkverwaltungseinrichtung

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A2

Designated state(s): CN DE US

AK Designated states

Kind code of ref document: A3

Designated state(s): CN DE US

DFPE Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)
REF Corresponds to

Ref document number: 10080454

Country of ref document: DE

Date of ref document: 20010726

WWE Wipo information: entry into national phase

Ref document number: 10080454

Country of ref document: DE