摘要
描述了一种新型的访问控制模型,用格的结点表示与访问对象相关的访问权限,访问权限的变化映射在格上成为一个结点到另一个结点的变换.在模型中,实现了访问控制策略实时更新,加强了并发控制环境中系统的安全性.为保证访问控制策略更新的合法性,建立了访问权限与授权级别相结合的复合格,可按权限级别进行访问权限控制.在并发环境中,多个主体读写数据和修改访问控制策略并互相影响时,可直接应用文中的模型与算法.
A new access control model is described. All possible access control privileges pertaining to an object can be represented as the nodes on the access control lattice of the object. The update of access control policy changes the mapping of the subject access privilege from one node to another in the access control lattice of object. The access control policy of real-time update is given in the model so that the system security is strengthened in a concurrent environment. In order to guarantee legitimacy of access control policy update, the compound lattice of an operation right lattice and an authorization level lattice are built. Access privilege can be controlled by authorization. The model and algorithms are useful for concurrent environment in which multiple subjects access and modify the access control policies.
出处
《江苏大学学报(自然科学版)》
EI
CAS
北大核心
2008年第2期151-154,共4页
Journal of Jiangsu University:Natural Science Edition
基金
国家"863"计划资助项目(2002AA001020)
关键词
信息安全
访问控制
格
实时更新
事务
锁模型
information security
access control
lattice
real-time update
transaction
lock model