摘要
在网格环境下,如何解决跨管理域的访问控制问题是实现资源共享和协同工作的关键。文中在基于角色的访问控制机制下,提出了一种基于协商的跨域访问控制模型并对其进行了形式化描述。各个域通过共同协商来定义、分配虚拟角色,用户以虚拟角色来实现虚拟组织内的跨域访问。此外,模型以访问控制策略的形式引入了计算对上下文信息的约束,从而能够支持上下文敏感的访问控制。
In grid environments, how to solve cross-domain access control is the key to sharing resources and working coordinately. This paper proposes a negotiation-based cross-domain access control model, and then gives the description of its formalization. In this model, all member domains define and assign virtual roles by negotiating together, the users initiate a cross-domain access in virtual roles. In addition, constraints on access context information are introduced as access control strategies, thus to support context-sensitive access control.
出处
《信息安全与通信保密》
2009年第8期130-133,共4页
Information Security and Communications Privacy
基金
国家863基金资助项目(2006AA012457).
关键词
网格计算
协商
跨域
访问控制
grid computing
negotiation
cross domain
access control