超越集中式策略决策点:通过证据法定人数的去中心化粘性策略授权
Beyond Centralized Policy Decision Points: Decentralized Sticky Policy Authorization through Evidence Quorums
- Bernal Institute, University of Limerick(利默里克大学伯纳尔研究所)
- Munster Technological University(芒斯特科技大学)
- South East Technological University(东南科技大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
SPEAR-Q通过独立策略权威节点的多数证据法定人数实现去中心化粘性策略授权,无需集中式决策点,实验验证了其有效性与故障关闭特性。
AI中文摘要:
粘性策略始终附着于受保护数据,以便访问限制能够在不同系统中持续存在,然而请求时的授权通常仍依赖于集中式可信机构或策略决策点(PDP)。本文提出SPEAR-Q,一个去中心化框架,其中独立的策略权威节点(PANs)利用本地上下文、同意和风险信息评估活动的粘性策略,并生成签名的授权证据。严格多数的证据法定人数决定全局允许或拒绝决策,而提交的策略仅在所需PAN多数应用后才变为活动状态。SPEAR-Q在空客网络安全仿真平台中部署于物理分离的主机上,并使用源自MIMIC-IV的医疗工作负载进行评估。在9,000个性能请求中,所有请求均完成,无执行失败或超时。随着集群规模和并发性的增长,延迟增加且吞吐量饱和,PAN证据等待和PAN本地处理在负载下占主导,而凭证验证构成主要的PAN侧成本。策略激活实验确认了基于多数的激活。法定人数实验表明,来自少于所需法定人数的受损PAN的正确签名的虚假允许证据无法产生全局允许或资源释放,而当可达PAN低于所需法定人数时,授权保持故障关闭。与先前分别去中心化策略管理、凭证权威或基于阈值的发布的方法相比,SPEAR-Q在一个去中心化框架内集成了持久粘性策略执行、独立的请求时证据、基于多数的策略激活和明确的法定人数限定的授权。在评估条件下,SPEAR-Q支持去中心化粘性策略授权,而不依赖集中式决策权威。
英文摘要:
Sticky policies remain attached to protected data so that access restrictions can persist across systems, yet request-time authorization often still depends on a centralized Trusted Authority or Policy Decision Point (PDP). This paper presents SPEAR-Q, a decentralized framework in which independent Policy Authority Nodes (PANs) evaluate the active sticky policy using local context, consent, and risk information and generate signed authorization evidence. A strict-majority Evidence quorum determines the global Permit or Deny decision, while a committed policy becomes active only after the required PAN majority applies it. SPEAR-Q was deployed across physically separated hosts in the Airbus Cyber Security Simulation Platform and evaluated using a healthcare workload derived from MIMIC-IV. Across 9,000 performance requests, all requests completed without execution failure or timeout. Latency increased and throughput saturated as cluster size and concurrency grew, with PAN evidence waiting and PAN-local processing dominating under load and credential validation forming the main PAN-side cost. Policy-activation experiments confirmed majority-based activation. Quorum experiments showed that correctly signed false-Permit evidence from fewer compromised PANs than the required quorum could not produce a global Permit or resource release, while authorization remained fail-closed when reachable PANs fell below the required quorum. Compared with prior approaches that decentralize policy management, credential authority, or threshold-based release separately, SPEAR-Q integrates persistent sticky policy enforcement, independent request-time evidence, majority-based policy activation, and explicit quorum-bounded authorization within one decentralized framework. Under the evaluated conditions, SPEAR-Q supports decentralized sticky-policy authorization without relying on a centralized decision authority.