摘要
提出了一种用于分布式计算环境的语言安全策略语言SSPL。SSPL通过OWLDL描述,支持各种安全策略的基本类型,包括肯定和否定授权,肯定和否定义务,权限委托和撤销以及策略冲突消除等。SSPL还支持基于规则的安全策略,使得该语言具有更强的表达能力。为了分析SSPL策略的形式化语义和推理的可判定性,引入DL-safe规则和courteous logic program的概念,并定义了一组从SSPL策略到courteous DL-safe program的转换规则,介绍了对转换得到的逻辑程序的推理过程。
A semantic security policy language, called SSPL, was proposed for distributed computing environment. SSPL is represented in OWL DL. SSPL supports basic concepts of security policy-positive and negative authorization and obligation, privilege delegation and revocation, policy conflict resolution. Furthermore, SSPL supports rule-style policy, which enhances the expressiveness of SSPL. This paper also demonstrates the reasoning of SSPL policy. DL-safe rule and courteous logic program were introduced for the formal semantic of SSPL. The transformation from SSPL policy to courteous DL-safe program and the query answering procedure of the result courteous DL-safe program are presented.
出处
《北京大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2006年第5期646-657,共12页
Acta Scientiarum Naturalium Universitatis Pekinensis
基金
中澳科技合作特别基金资助项目(2004-443-4)