摘要
本文采用Clark-Wilson完整型模型,使用属性证书作为权限传递的载体,结合授权管理基础设施(PMI)实现基于角色的授权模型,并提出一种形式化描述架构,描述权限、证书和相关的授权;基于语义的演算过程对给定的属性证书集和撤销证书集可以验证某种权限是否有效;采用Alloy形式化语言来定义模型,并且给出描述扩展Clark-Wilson的方法。
The Clark-Wilson-based integrity model is introduced, and the privilege management infrastructure is studied,and a role-based authorization model is implemented with attribute certificates,and then a formal description framework is put forward to describe privilege,certificates and interrelated authorization.The semantics-based calculation can verify privilege by some appointed attribute certificate sets and revocation certificate sets.Finally,the model is defined with the Alloy formal language,and a method of expanding the Clark-Wilson model is also presented.
出处
《计算机工程与科学》
CSCD
2007年第3期23-26,共4页
Computer Engineering & Science