摘要
网格的安全性因其广泛的资源共享和动态、多域的异构环境而显得极为复杂.网格安全基础设施(GSI)可以解决身份鉴别、保密性和完整性问题,却难以有效解决访问控制问题,传统的访问控制模型也不能很好的满足网格的安全需求.本文在华中科技大学计算网格平台基础上,研究并提出了一种基于任务的计算网格访问控制模型,该模型通过定义授权步和任务状态及系统条件约束,能动态地控制主体访问资源的权限,具有较好的通用性、灵活性和可扩展性,并已在计算网格实验平台中得到了实现.
Grid security is complicated on account of pervasive resource sharing and dynamic, multi-domains heterogeneous computing enverioment. The grid security infrastracture (GSI) is emerged for identify authentification, data confidentiality and integrity, but can not solute problems about access control well. Traditional model of access control can not satify security re- querments of grid either. This paper describes a task-based access control model for computing grid, basing on the HUST grid. The model defines authorization steps, task status and system conditions, and pemissions can be dynamically controled. This model is enforced in computing grid experimental platform, and proved to be universal, flexible and extendable.
出处
《小型微型计算机系统》
CSCD
北大核心
2008年第1期85-88,共4页
Journal of Chinese Computer Systems
基金
国家自然科学基金项目(60403027
60273076)资助