期刊文献+

一个通用的分布式访问控制决策中间件 被引量:6

Universal distributed access control decision middleware
下载PDF
导出
摘要 将各种安全功能从上层应用中抽象出来形成一种通用和标准的安全服务,可以简化应用开发的复杂性和增强安全功能的可重用性。论文设计并实现了一个基于XACML的通用分布式访问控制决策中间件UDACD(Universal Distributed Access Control Decision),对分布式环境下的访问控制决策过程进行了封装,对外面向各种应用提供通用的决策服务。UDACD支持多种访问控制策略类型和跨管理域的匿名资源访问控制;实现了对策略的缓存和对用户安全属性的两级缓存,显著加快了决策速度。UDACD可以帮助简化策略管理,并提供跨应用的一致策略实施。 To separate security functions from applications and reconstruct them into universal and standard services can help simplify the development of applications and make the security functions reusable.In the paper,a Universal Distributed Access Control Decision (UDACD) middleware which employs XACML is designed and implemented.It encapsulates the details of access decision and provides universal decision services to various kinds of distributed applications.UDACD can enforce multiple kinds of policies at the same time and support cross-domain anonymous resource access control.It employs policy cache and two levels of attribute caches,which can remarkably accelerate decision speed.It can help simplify policy administration and provide consistent policy enforcement among multiple applications.
出处 《计算机工程与应用》 CSCD 北大核心 2008年第1期17-20,24,共5页 Computer Engineering and Applications
基金 国家自然科学基金(the National Natural Science Foundation of China under Grant No.60603017) 国家高技术研究发展计划(863)(theNational High-Tech Research and Development Plan of China under Grant No.2006AA01Z454) 国家科技支撑计划(No.2006BAH02A02)。
关键词 访问控制 访问控制决策 跨域访问控制 XACML access control access control decision cross-domain access control XACML
  • 相关文献

参考文献14

  • 1ISO/IEC.ISO/IEC 10181-3 open systems interconnection-security frameworks for open systems:access control framework[S],1996.
  • 2Yuan E,Tong Jin.Attributed Based Access Control(ABAC) for Web services[C]//Proceedings of the IEEE International Conference on Web Services (ICWS'05).Washington:IEEE Computer Society,2005:561-569.
  • 3Ferraiolo D F,Gavrila S,Hu V,et al.Composing and combining policies under the policy machine[C]//Proceedings of the tenth ACM symposium on Access control Models and Technologies.NewYork:ACM Press,2005:11-20.
  • 4Wang Lingyu,Wijesekera D,Jajodia S.A logic-based framework for attribute based access control[C]//Proceedings of the 2004 ACM workshop on Formal methods in security engineering.NewYork:ACM Press,2004:45-55.
  • 5OASIS.XACML v3.0 administration policy working draft[S],2006.
  • 6OASIS.Security Assertion Markup Language(SAML) Version 1.0[S],2002.
  • 7OASIS.eXtensible Access Control Markup Language(XACML) Version 1.0[S],2003.
  • 8OASIS.Core and hierarchical role based access control(RBAC) profile of XACML v2.0[S],2005.
  • 9刘琼波,施军,尤晋元.分布式环境下的访问控制[J].计算机研究与发展,2001,38(6):735-740. 被引量:18
  • 10Blaze M,Feigenbaum J,Lacy J.Decentralized trust management[C]//Proc of the 1996 IEEE Symposium on Security and Privacy.Oakland:IEEE Computer Press,1996:164-173.

二级参考文献1

  • 1Lupu E,IEEE Trans Software Engineering,1999年,25卷,6期,852页

共引文献17

同被引文献42

引证文献6

二级引证文献9

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部