WO2000051288A2 - Modification de la recommandation x.741 de l'uit-t pour une protection d'acces unitaire a des objets geres et a des fichiers de donnees - Google Patents
Modification de la recommandation x.741 de l'uit-t pour une protection d'acces unitaire a des objets geres et a des fichiers de donnees Download PDFInfo
- Publication number
- WO2000051288A2 WO2000051288A2 PCT/DE2000/000517 DE0000517W WO0051288A2 WO 2000051288 A2 WO2000051288 A2 WO 2000051288A2 DE 0000517 W DE0000517 W DE 0000517W WO 0051288 A2 WO0051288 A2 WO 0051288A2
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- managed objects
- recommendation
- file
- access
- attribute
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6236—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database between heterogeneous systems
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/04—Network management architectures or arrangements
- H04L41/052—Network management architectures or arrangements using standardised network management architectures, e.g. telecommunication management network [TMN] or unified network management architecture [UNMA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/28—Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2141—Access rights, e.g. capability lists, access control lists, access tables, access matrices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2145—Inheriting rights or properties, e.g., propagation of permissions or restrictions within a hierarchy
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
Definitions
- the ITU-T (International Telecommunication Union, Telecommunications Standardization Sector) recommendation X.741 is currently only intended for access protection of managed objects.
- the subject matter of the application relates to a method for realizing uniform access protection to managed objects and files based on ITU-T recommendation X.741, comprising the features of the preamble of claim 1, 4 or 5.
- ITU-T recommendation M.3010 describes the architecture and interfaces of a Telecommunication Management Network TMN.
- the interface between operations systems and network elements is designated Q 3 , that between the operations systems is designated X.
- CMIP Common Management Information Protocol
- ITU-T rec X.710 / X.711 was developed and managed objects were introduced, in which the management information is stored .
- the managed objects are administered with CMIP.
- the managed objects are processed in accordance with the ITU-T rec. X.720 to X.722 described with GDMO (Guidelines for the Definition of Managed Objects). In practice, this implementation of the Q 3 and X interfaces is not sufficient.
- mass data e.g.
- ITU-T rec. X.741 interprets and applies the model described in ITU-T X.812 for access control to management applications that use CMIP as the management protocol. It defines an object model with which access rights can be managed at the object class, object instance, attribute and attribute value level. A direct application of the ITU-T rec. X.741 on file access is not possible.
- the subject of the registration is based on the problem described in ITU-T rec. Adapt the object model described in X.741 so that it can be used uniformly both for access protection for managed objects and for access protection for files.
- the subject of the application makes use of the knowledge that the ITU-T rec. X.741 described schemes (access control list schemes, label based schemes, context based schemes or capacity based schemes) for an access control to which managed objects can be transferred to a file access control.
- the subject of registration is ITU-T rec. X.741 in such a way that it is used to protect files accessed by file trans- fer (e.g. with FTAM or FTP) is made usable.
- Access protection to managed object classes and files is implemented in a uniform form, which means that an operator for access protection offers uniform handling (look and feel) and uniform management. Synergy effects can be achieved when implementing uniform access protection.
- the file access protection provided by the subject of the application is independent of the file management system and of the access method. It can be used, for example, for FTAM (ISO 8571) and for FTP (RFC (Request for Comments) 959 and 1123).
- the object of registration can be executed as a separate model for file protection.
- FIG. 1 shows a basic illustration of the general relationship of a telecommunications management network to a telecommunications network
- FIG. 2 shows an exemplary embodiment for the simplified physical architecture of a telecommunications management network ⁇ and FIG. 3 relationships in an object model.
- ITU-T rec. M.3010 describes the architecture and the interface ⁇ provide a Telecommunications Management Network TMN.
- the interface between the operations systems and network elements is designated by Q, that between the operations systems by X.
- a Data Communication Network DCN consists of several operating systems OS, a workstation WS, another telecommunications management network oTMN (for: other telecommunications management network) and several switching devices EX (for: Exchange) and several transmission devices TR (for: Transmission) connected.
- the switching devices EX and the transmission devices TR which are alternately connected to one another, belong to the telecommunications network TN.
- a data processing device TEPC for: telecommunication terminal personal computer
- a telephone device TEF for: telecommunication terminal telephone
- the data communication network DCN is via an interface X, an interface F or an interface Q 3 ⁇ it with one or more operating systems OS, via an interface F with one or more workstations WS, via an interface Q 3 or an interface F to one or more devices MD (for: mediation device), via an interface Q 3 to one or more network elements NE, via an interface Q 3 to one or more QA and can be connected via an interface X to another telecommunication management network (not shown).
- the device MD is connected to one or more devices QA via an interface Q x (for: Q adapter) and an interface Q x connected to one or more network elements NE.
- the ITU-T rec. Schemes described in X.741 access control list schemes, label based schemes, context based schemes or capacity based schemes) for access control to the managed objects are transferred to a file access control according to the application.
- the in the object model of the ITU-T rec. X.741 described CMIP operations to which file accesses are adapted. These adjustments are essentially based on an expansion of the behavior, an expansion of the attribute syntax and the definition of new attributes and actions. The following changes are made:
- Access control rules object class defaultAccess attribute the attribute syntax is extended to the file access methods such as “create”, “delete”, “read”, “write”, “readAttributes”, “execute”, “noOperation” ... deni- alGranularity Attribute: the attribute syntax is expanded to include values that relate to the granularity of the file access, such as “fileOperation” and "singleFile”. The behavior of the attribute is adjusted accordingly.
- Behavior The behavior is expanded by the following sentence: "If the targets list attribute identifies files, then the initiators list attribute must identify initiators in the context of a file access scheme.”
- Behavior should be expanded to "managed objects or files”.
- the object class is expanded by attributes for file selection (such as fileType, fileName) and by optional attributes in which conditions for file selection can be formulated (such as fileFilter, fi lePatternList to identify file names according to a defined pattern).
- OperationsListPackage operationsList attribute: the attribute syntax refers to the ASN.l (Abstract Syntax Notation No 1) type "operationType". This type is extended by values for file access methods such as "create”, “delete”, “read”, “write”, “readAttributes”, “execute”, “noOperation” ... An access protection password can be optionally defined for each method . The behavior of the attribute is adjusted accordingly.
- the package should be extended by the actions "resetPassword” (resetting an access protection password to a predefined value) and “cancelPassword” (removing an access protection password).
- An access protection password can be optionally defined for each method. The behavior of the attribute is adjusted accordingly.
- the actions “resetPassword” (resetting an access protection password to a predefined value) and “cancelPassword” (removing an access protection password) should be added.
- Capability initiators object class capabilityldentitiesList Attribute the attribute syntax refers to the ASN.l type "operationType". This type is extended by values for file access methods such as “create”, “delete”, “read”, “write”, “readAttributes”, “execute”, “no ⁇ Operation” ... An access protection password can be optionally defined for each method. The behavior of the attribute is adjusted accordingly.
- Object model The previously used in the ITU-T rec.
- the X.741 defined object model remains unchanged and is extended allomorphically by the subclasses required for file access protection.
- the allomorphic extension of the object model is understood to mean that an object model derived from a given object model is handled as an instance of an object model.
- the aim of this type of implementation is to define and reuse already defined object classes that can still be used for file access protection.
- 3 shows the example of relationships in an object model in which an object class access control AC (for: accessControl) in the course of inheritance IH (for: inheritance) an object class access control scheme ACR (for: accessControlRules) and an object class file- Access control scheme FACR (for: fileAccessControlRules) can be formed.
- AC for: accessControl
- ACR object class access control scheme
- FACR object class file- Access control scheme
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Bioethics (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Databases & Information Systems (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
- Storage Device Security (AREA)
Abstract
La recommandation X.741 de l'UIT-T prévue depuis longtemps seulement pour la protection d'accès à des objets gérés est modifiée de telle sorte qu'elle soit également adaptée à une protection d'accès à des fichiers de données, ce qui offre une protection d'accès unitaire avec une manipulation unitaire et une gestion unitaire. Des formes d'exécutions particulières de l'objet de la demande sont données par adjonction, en complément, au modèle d'objet existant pour une protection d'accès à des objets gérés, d'un autre modèle d'objet pour une protection d'accès à des fichiers de données, par élargissement du modèle d'objet existant pour une protection d'accès à des objets gérés avec des sous-classes pour une protection d'accès à des fichiers de données et par élargissement du modèle d'objet existant pour le transformer en un nouveau modèle d'objet pour objets gérés et fichiers de données. L'objet de la demande peut être réalisé sous la forme d'un modèle autonome pour la protection de fichiers de données.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE10080454T DE10080454D2 (de) | 1999-02-26 | 2000-02-24 | Modifizierung der ITU-T recommendation X.741 für einen einheitlichen Zugriffsschutz auf Managed Objects und Dateien |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE19908429.7 | 1999-02-26 | ||
| DE19908429 | 1999-02-26 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| WO2000051288A2 true WO2000051288A2 (fr) | 2000-08-31 |
| WO2000051288A3 WO2000051288A3 (fr) | 2000-12-21 |
Family
ID=7899015
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/DE2000/000517 Ceased WO2000051288A2 (fr) | 1999-02-26 | 2000-02-24 | Modification de la recommandation x.741 de l'uit-t pour une protection d'acces unitaire a des objets geres et a des fichiers de donnees |
Country Status (2)
| Country | Link |
|---|---|
| DE (1) | DE10080454D2 (fr) |
| WO (1) | WO2000051288A2 (fr) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE10146361B4 (de) * | 2001-09-20 | 2007-02-01 | Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V. | Verteiltes System |
| JP2008029094A (ja) * | 2006-07-20 | 2008-02-07 | Hitachi Ltd | 電力変換装置 |
| JP2017131061A (ja) * | 2016-01-21 | 2017-07-27 | ヤンマー株式会社 | 電力変換装置及びその組み立て方法 |
-
2000
- 2000-02-24 DE DE10080454T patent/DE10080454D2/de not_active Expired - Fee Related
- 2000-02-24 WO PCT/DE2000/000517 patent/WO2000051288A2/fr not_active Ceased
Non-Patent Citations (4)
| Title |
|---|
| "ITU-T Recommendation X.741 Corrigendum 1" ITU-T INTERNATIONAL TELECOMMUNICATION UNION, 1. Oktober 1996 (1996-10-01), Seiten 1-123, XP002144722 in der Anmeldung erw{hnt * |
| "X.741 Recommendation" ITU-T INTERNATIONAL TELECOMMUNICATION UNION, 1. April 1995 (1995-04-01), Seiten 1-1-123, XP002144721 in der Anmeldung erw{hnt * |
| NETWORK WORKING GROUP: "RFC 959 - FTP - File Transfer Protocol" INTERNET RFCS, 1. Oktober 1985 (1985-10-01), XP002144723 in der Anmeldung erw{hnt * |
| START K ET AL: "The distribution management of service software" COMPUTER STANDARDS AND INTERFACES,CH,ELSEVIER SEQUOIA. LAUSANNE, Bd. 17, Nr. 3, 1. Juni 1995 (1995-06-01), Seiten 291-301, XP004008584 ISSN: 0920-5489 * |
Cited By (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE10146361B4 (de) * | 2001-09-20 | 2007-02-01 | Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V. | Verteiltes System |
| JP2008029094A (ja) * | 2006-07-20 | 2008-02-07 | Hitachi Ltd | 電力変換装置 |
| US7751201B2 (en) | 2006-07-20 | 2010-07-06 | Hitachi, Ltd. | Power converter |
| JP2017131061A (ja) * | 2016-01-21 | 2017-07-27 | ヤンマー株式会社 | 電力変換装置及びその組み立て方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| DE10080454D2 (de) | 2001-07-26 |
| WO2000051288A3 (fr) | 2000-12-21 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE69319103T2 (de) | Netzwerkverwaltungssystem | |
| DE69529846T2 (de) | Verfahren zum vergleich von attributwerten von steuerbaren objektausdrücken in einem netzwerkelement | |
| DE69333960T2 (de) | Namenauflösung in einem Mehrsystem-Netz | |
| DE69510226T2 (de) | Verfahren und vorrichtung zur aktualisierung oder änderung eines netzwerkverzeichnisses | |
| DE69738309T2 (de) | Verteilte verarbeitung | |
| DE69832946T2 (de) | Verteiltes System und Verfahren zur Steuerung des Zugriffs auf Netzmittel und Ereignismeldungen | |
| DE69424597T2 (de) | Erweiterbares Dateiensystem | |
| DE69726853T2 (de) | System und verfahren zum totalen kommissionieren von telekommunikationsdiensten | |
| DE69425093T2 (de) | Verfahren zum Erzeugen einer Gruppe erweiterbarer Zusatzdienste für Objekte in einem objektoriertierten System | |
| EP0959588A2 (fr) | Elément de réseau avec le dispositif de commande et la méthode de contrÔle | |
| EP0520083B1 (fr) | Protection de la consistance des données dans un système de télécommunications numériques | |
| DE69634650T2 (de) | Telekommunikationsdienstwechselwirkungen | |
| EP0825524A1 (fr) | Procédé pour nommer des objets | |
| DE3782349T3 (de) | Netzwerk-Ereignisseidentifikationseinrichtungen. | |
| DE69427198T2 (de) | Kommunikationssystem mit einem ein verwaltungsmodul einschliessendem netz | |
| DE10115722A1 (de) | Effiziente Echtzeitverwaltung von Speicherbetriebsmitteln | |
| DE69833845T2 (de) | Intelligente Schnittstelle zwischen einem Dienststeuerpunkt und einem Signalisierungsnetz | |
| EP0557566B1 (fr) | Méthode d'accès par mot de passe administré hiérarchiquement aux indications d'accès d'utilisateur dans une base de données d'un central à commande programmée | |
| DE10110039A1 (de) | Ein Verfahren zur generischen Beschreibung und Manipulation beliebiger Datenstrukturen | |
| DE19930119C2 (de) | Prioritätsverwaltungsverfahren | |
| EP0850545A1 (fr) | Systeme environnemental operationnel pour des applications de services d'un reseau de telecommunication | |
| DE19534207A1 (de) | Verfahren zur Kodierung oder Dekodierung von Protokolldateneinheiten (PDU) | |
| EP0614551B1 (fr) | Procede de commande de l'interaction entre une interface utilisateur et une application | |
| EP1157566A1 (fr) | Procede et element de reseau pour exploiter un reseau de telecommunication | |
| DE19922853A1 (de) | Verfahren zur Ausführung einer Anforderung einer Netzwerkverwaltungseinrichtung |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| AK | Designated states |
Kind code of ref document: A2 Designated state(s): CN DE US |
|
| AK | Designated states |
Kind code of ref document: A3 Designated state(s): CN DE US |
|
| DFPE | Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101) | ||
| REF | Corresponds to |
Ref document number: 10080454 Country of ref document: DE Date of ref document: 20010726 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 10080454 Country of ref document: DE |