摘要
资源授权决策是协作信息系统面临的首要安全问题。首先结合角色、时态和环境的概念,介绍了行为的含义和基于行为的访问控制模型ABAC(action-based access control model),然后基于ABAC模型,给出了协作信息系统访问控制机制的流程;提出了包含用户请求、用户身份、口令、角色、时态状态、环境状态、生命期等安全属性的安全关联及其产生方法;给出了一种安全认证协议,使用此协议可以实现用户与行为服务器、资源管理服务器之间交换与ABAC模型相关的安全属性,并使用UC模型证明该协议的安全性。
The authorization decision on resources is the major problem in collaborative information systems. Firstly, the term "action" was defined based on roles, temporal states and environmental states, and the action-based access control (ABAC) model was presented. Then, the access control mechanism based on ABAC for collaborative information systems was introduced. The security association was defined and its producing procedure was proposed, which contains security properties such as user request, user identity, password, role, temporal state, environmental state and lifetime. Finally, to exchange the security properties among user, action server and resources management server, a secure authentication protocol was proposed, and its security was proven under the universally composable model.
出处
《通信学报》
EI
CSCD
北大核心
2008年第9期116-123,共8页
Journal on Communications
基金
国家高技术研究发展计划(“863”计划)基金资助项目(2007AA01Z472,2007AA01Z429,2007AA01Z482)
国家自然科学基金资助项目(60633020,60573036,60702059)~~
关键词
访问控制
协作信息系统
安全关联
认证协议
access control
collaborative information system
security association
authentication protocol