期刊文献+

基于属性的访问控制策略描述语言(英文) 被引量:6

Attribute-based access control policy specification language
下载PDF
导出
摘要 首先提出了基于属性的访问控制策略,该方法利用用户和角色属性表达式来描述访问控制策略.然后,提出了扩展的XACML(扩展访问控制标记语言)策略描述语言A-XACML.A-XACML可以简单、灵活地表达各种应用环境中的访问控制策略,尤其是基于属性的访问控制策略.该语言及其框架通过数据类型、函数和逻辑组合来定义简单或复杂的访问控制策略.最后,给出了利用属性表达式和A-XACML来实现用户-角色指派的系统架构和应用实例.该实例表明属性表达式和A-XACML能够灵活简单地描述和实施复杂的访问控制策略. This paper first introduces attribute expression to describe attribute-based access control policy.Secondly,an access control policy enforcement language named A-XACML (attribute-XACML)is proposed,which is an extension of XACML.A-XACML is used as a simple,flexible way to express and enforce access control policies,especially attribute-based access control policy,in a variety of environments.The language and schema support include data types,functions,and combining logic which allow simple and complex policies to be defined.Finally,a system architecture and application case of user-role assignment is given to show how attribute expressions and A-XACML work in access control policy description and enforcement.The case shows that attribute expression and A-XACML can describe and enforce the complex access control policy in a simple and flexible way.
出处 《Journal of Southeast University(English Edition)》 EI CAS 2008年第3期260-263,共4页 东南大学学报(英文版)
基金 The National High Technology Research and Development Program of China(863Program)(No.2007AA01Z445)
关键词 基于角色的访问控制 策略 XML XACML role-based access control policy XML XACML
  • 相关文献

参考文献6

  • 1Godik Simon,Moses Tim,Anderson Anne,et al.OASIS ex-tensible access control markup language(XACML). http://www.oasis-open.org/committees/xacml/ . 2008
  • 2Toktar E,Jamhour E,Maziero C.RSVP policy control using XACML[].Proc of POLICY.2004
  • 3Al-Kahtani Mohammad Abdullah.A family of models for rule-based user-role assignment[]..2003
  • 4SANDHU Ravi,COYNE Edward,FEINSTEIN Hal,et al.Role-based access control models[].IEEE Computer.1996
  • 5BHATTI R,BERTINO E,GHAFOOR A.XML-based specification for web services document security[].IEEE Compt.2004
  • 6Joshi J B D,Bhatti R,Bertino E,et al.Access Control Lan-guage for Multidomain Environments[].IEEE Internet Computing.2004

同被引文献64

引证文献6

二级引证文献31

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部