摘要
本文详细介绍了特权管理基础设施(PMI,PrivilegeManagementInfrastructure),并在分析了网络访问控制的关键因素后提出PMI的定义,PMI在访问控制中的需求以及PMI的模型。本文研究的重点有两个方面,一是对属性证书的各个域的具体含义作了详细描述,并且分析了各个域在访问控制及证书的管理的过程中的作用;二是提出了简单PMI模型、PMI访问控制模型以及PMI委托模型三个适用于不同的访问控制环境的模型,为具体系统的实现提供了理论基础。最后,本文对属性证书管理中几个重点细节的技术进行了详细的比较。
In this paper we introduce Privilege Management Infrastructure (PMI) in detail. After the analysis of the key factors of access control in network, we present the definition of PMI , the requirements of PMI for the access control, and several models of PMI. The two main points of this paper, one is detailed description of every field of Attribute Certificate and its function in access control. And the other is to present the simple model of PMI, PMI access control model and PMI delegation model, which suit different environments of access control respectively. At the end of the paper, several important techniques in the management of attribute certificates are presented.
出处
《微计算机应用》
2005年第4期398-401,共4页
Microcomputer Applications