期刊文献+

动态安全模型中基于代理的访问控制 被引量:1

Agent-based Access Control for Dynamic Security Model
下载PDF
导出
摘要 随着信息系统复杂性不断增强,许多大型应用系统都具有动态性,但是传统的访问控制机制不能提供动态权限分配。该文提出一个实现动态安全策略的访问控制模型,在RBAC模型基础上通过代理动态地决定访问权限,代理根据抽象角色定义和上下文信息规则,通过推导模块得到用户的实际角色,阐述模型的组成并将它应用于一个项目管理系统中。结果表明,该模型比传统的访问控制模型更加高效安全。 With the development of information system,most practical applications have dynamic attributes,but conventional access control mechanisms have not addressed the problem efficiently.This paper discusses how to realize an access control system that enables to manage dynamic security policies.The proposed method is based on Role-based Access Control(RBAC),and the agent decides access rights dynamically for the abstract role,according to the definitions of the abstract roles,context information and rules,agent acquire actual role by inference module,demonstrate the structure of the model and usefulness of the proposed system by presenting the project management application and its access control system.Experimental results verify that the model is more efficient and securer than traditional access control model.
出处 《计算机工程》 CAS CSCD 北大核心 2008年第8期193-194,197,共3页 Computer Engineering
关键词 访问控制 安全模型 抽象角色 代理 access control security model abstract role agent
  • 相关文献

参考文献5

  • 1Ferraiolo D F, Barkly J F, Kuhn D R. A Role Based Access Control Model and Reference Implementation Within a Corporate Internet[J]. ACM Transactions on Information Systems Security, 1999, 1(1): 23-31.
  • 2Giuri L, Iglio E Role Templates for Content Based Access Control[C]//Proceedings of the 2nd ACM Workshop on Role Based Access Control. [S. l.]: ACM Press, 1997: 153-159.
  • 3Zhang Longhua, Gail-Joon A, Bei-Tseng C. A Rule-based Framework for Role-based Delegation and Revocation[J]. ACM Transactions on Information and System Security, 2003, 6(3): 404-441.
  • 4Convington M. Securing Context Aware Applications Using Environment Roles[C]//Proc. of the 13th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises. [S. l.]: IEEE Press, 2001: 10-20.
  • 5Kern A, Schaad A; Moffett J. Enterprise Role Administration: an Administration Concept for the Enterprise Role-based Access Control Model[C]//Proc. of the 8th ACM Symposium on Access Control Models and Technologies. [S.l.]: ACM Press, 2003: 33-40.

同被引文献1

引证文献1

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部