期刊文献+

基于逻辑的访问控制研究 被引量:1

Research of Logic-based Access Control
下载PDF
导出
摘要 描述了访问控制和逻辑的关系,并将访问控制授权判决问题归约成逻辑蕴涵问题;总结了基于逻辑的访问控制的基本逻辑问题,即逻辑基础、可判定性和安全性分析;分析了一些访问控制模型的基本逻辑问题,包括基于身份的访问控制模型、基于信任管理的访问控制模型和基于属性的访问控制模型;指出了结构化属性描述能力和安全性分析是基于逻辑的访问控制需要进一步研究的问题。 This paper addressesd the relation between access control and logic, reduced authorization decision to logic containment, and studied the basic logical issues of access control, namely logical foundation, decidability and security analysis. Then, the paper researched the basic issues of some access control models, which include identity based, trust management based and attribute based access control model. Lastly, the paper discussed the research direction of the logic-based access control, which includes structure attribute logic and security analysis.
出处 《计算机科学》 CSCD 北大核心 2009年第4期42-46,共5页 Computer Science
基金 国家高技术研究发展计划(863)(No.2007AA01Z471)资助
关键词 访问控制 逻辑 可判定性 安全性分析 Access control,Logic,Decidability,Security analysis
  • 相关文献

参考文献43

  • 1Sandhu R S, Samarati P. Access Control: Principles and Practice [J]. IEEE Communication, 1994,32 (9) : 40-48
  • 2Lampson B W. Protection[C] //Proceedings of 5th Princeton Symposium on Information Science and Systems. 1971:437-443
  • 3Sandhu R S. The Typed Access Matrix Model[C]//Proceedings of the 1992 IEEE Symposium on Security and Privacy. IEEE Computer Society Press, 1992 : 122-136
  • 4Lampson B, Abadi M, Burrows M, et al. Authentication in Distributed Systems:Theory and Practice [J]. ACM Transaction on Computer Systems, 1992,10 (4) : 265-310
  • 5Abadi M, Burrows M, Lampson B, et al. A calculus for access control in distributed systems[J]. ACM Transactions on Programming Languages and Systems, 1993,15 (4) : 706-734
  • 6Abadi M. Logic in Access Control[C]//Proceedings of 18th Annual IEEE Symposium on Logic in Computer Science (LICS' 03). 2003 : 228
  • 7Woo T Y C, Lam S S. Authorization in Distributed Systems--a Formal Approach[C]//Proceedings of the IEEE Symposium on Security and Privacy. Oakland,CA, 1992
  • 8Woo T Y C, Lam S S. Authorization in Distributed Systems-A New Approach[J]. Journal of Computer Security, 1993,2(2/3) : 107-136
  • 9Woo T Y C , Lam S S. Designing a Distributed Authorization Service//Proceedings of Seventeenth Annual Joint Conference of the IEEE Computer and Communications Societies (INFOCOM 1998). vol. 2, IEEE Press, 1998 : 419-429
  • 10Woo T Y C,Lam S S. A Framework for Distributed Authorization (extended abstract) [C] /// Proceeding of 1st ACM Conference on Computer and Communication Security. Fairfax, Virginia, November 1993:112-118

二级参考文献1

共引文献66

同被引文献27

  • 1徐震,李斓,冯登国.基于角色的受限委托模型[J].软件学报,2005,16(5):970-978. 被引量:52
  • 2钟勇,秦小麟,郑吉平,林冬梅.一种灵活的使用控制授权语言框架研究[J].计算机学报,2006,29(8):1408-1418. 被引量:15
  • 3Sloman M S. Policy Driven Management for Distributed Systems [J]. Journal of Network and Systems Management, 1994,2(4): 333-360.
  • 4Woo T Y C, Lain S S. Authorizations in distributed systems: A new approach[J]. Journal of Computer Security, 1993, 2(2/3) : 107-136.
  • 5Sushil J, Samarati P. Flexible support for multiple access control Policies[J]. ACM Transactions on Database Systems, 2001,26 (2): 214-260.
  • 6Sushil J, Samarati P, Los Alamitos, et al. A unified framework for enforcing multiple access control policies[C] // Proceedings of the 1997 ACM SIGMOD international conference on Management of Data. New York, USA, 1997 : 474-485.
  • 7Sushit J, Samarati P, Subrahmanian V. A Logical Language for Expressing Authorizations[C]//Proceedings of IEEE Symposium on Security and Privacy. Oakland, Calif, USA, 1997 : 94-107.
  • 8Lobo J, Bhatia R, Naqvi S. A Policy Description Language[C]//Proceedings of the Sixteenth National Conference on Artificial Intelligence Eleventh Innovative Applications of AI Conference. Orlando, Florida, USA, 1999.
  • 9Damianou N. Tools for domain-based policy management of distributed systems [C]//Network Operations and Management Symposium. NOMS 2002. IEEE/IFIP, 2002.
  • 10Damianou N, Dulay N, Sloman M, et al. Ponder: A Language for Specifying Security and Management Policies for Distributed Systems[S]. The language Specification Version 2. 3. Imperial College of Science Technology and Medicine, Department of Computing, London, 2001.

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部