期刊文献+

开放网络环境中基于属性的通用访问控制框架 被引量:4

Attribute-based universal access control framework in open network environment
下载PDF
导出
摘要 针对传统访问控制模型在新一代可信互联网环境应用中存在用户角色赋值效率不高、跨域访问控制实现困难等局限性,提出了基于属性的通用访问控制框架。该框架对用户、资源、操作和上下文四类对象的属性信息进行统一的描述和处理,简化了传统RBAC及其他访问控制系统复杂的权限判定方式,从而增强了访问控制系统的通用性和灵活性;同时,对于跨域的访问应用了基于属性证书的验证方式并给出了相应的策略评估方案和评估算法,能够针对不同应用域中用户的访问需求动态实施资源管理和访问控制;另外,框架中引入的运行上下文对象机制,进一步提升了该框架对复杂、动态互联网环境的适应能力。 Concerning the limitations of the application of traditional access control model in new generation credible Interact environment, such as the inefficiency in user-role assignment and the difficulty in cross-domain access control, a universal attribute-based access control framework was proposed. It took a unified method to dispose the attributes of users, resources, operations and running context, simplified the complex way of permissions determination in traditional RBAC and other access control modes, thus enhancing the versatility and flexibility of access control system. At the same time, authentication based on attribute certificates was applied in cross-domain access, policy evaluation and evaluation algorithm were also discussed, which could dynamically realize resource management and access control for users from different domains. In addition, the mechanism of the running context makes the framework more suitable to be applied in complex and dynamic Internet environment.
作者 钟将 侯素娟
出处 《计算机应用》 CSCD 北大核心 2010年第10期2632-2635,2640,共5页 journal of Computer Applications
基金 国家科技支撑计划项目(2008BAH37B04)
关键词 开放网络环境 访问控制 属性 运行上下文 规则 open network environment access control attribute running context rule
  • 相关文献

参考文献12

  • 1SANDHU R S, COYNE E J, FEINSTEIN H L, et al. Role-based access control models [ J]. IEEE Computer, 1996, 29(2) : 38 - 47.
  • 2SANDHU R S, COYNE E J, FEINSTEIN H L, et al. Role-based access control: a muhi-dimensional view [ C]//Proceedings of 10th Annual Computer Security Applications Conference. Washington,DC: IEEE, 1994:54-62.
  • 3黄益民,平玲娣,潘雪增.一种基于角色的访问控制扩展模型及其实现[J].计算机研究与发展,2003,40(10):1521-1528. 被引量:42
  • 4严悍,张宏,许满武.基于角色访问控制对象建模及实现[J].计算机学报,2000,23(10):1064-1071. 被引量:58
  • 5YUAN E, TONG J. Attributed Based Access Control (ABAC) for Web Services [ C]/! ICWS'05: IEEE International Conference on Web Services. Washington, DC: IEEE Computer Society, 2005: 561 -569.
  • 6JOHNSTON W, MUDUMBAI S, THOMPSON M. Authorization and attribute certificates for widely distributed access control [ C ]// WETICE'98: Proceedings of the 7th International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises. Washington, DC: IEEE Computer Society, 1998:340-345.
  • 7ZHANG XINWEN, LI YINGJIU, NALLA D. An attribute-based access matrix model [ C]// Proceedings of the 2005 ACM Symposium on AppLied Computing. New York: ACM, 2005:359 -363.
  • 8叶春晓,钟将,冯永.基于属性的访问控制策略描述语言(英文)[J].Journal of Southeast University(English Edition),2008,24(3):260-263. 被引量:6
  • 9叶春晓,吴中福,符云清,钟将,冯永.基于属性的扩展委托模型[J].计算机研究与发展,2006,43(6):1050-1057. 被引量:17
  • 10李晓峰,冯登国,陈朝武,房子河.基于属性的访问控制模型[J].通信学报,2008,29(4):90-98. 被引量:80

二级参考文献54

  • 1沈海波,洪帆.面向Web服务的基于属性的访问控制研究[J].计算机科学,2006,33(4):92-96. 被引量:12
  • 2钟勇,秦小麟,郑吉平,林冬梅.一种灵活的使用控制授权语言框架研究[J].计算机学报,2006,29(8):1408-1418. 被引量:15
  • 3R S Sandhu, E J Coync, H L Fcinstcin et al. Role-based access control model. IEEE Computer, 1996, 29(2): 38-47.
  • 4R Sandhu, D Ferraiolo, R Kuhn. The NIST model for role-based access control: Towards a unified standard. In: Proe of the 5th ACM Workshop on Role Based Access Control. Berlin, Germany: ACM Press, 2000. 47-63.
  • 5K Izaki, K Tanaka, M Takizawa. Access control model in obiectoriented systems. In: Proc of the 7th Int'l Conf on Parallel and Distributed Systems: Workshops. Iwate, Japan: IEEE Computer Society, 2000. 69-74.
  • 6M J Moyer, M Ahamad. Generalized role-based access control. In: Proc of the 21st Int'l Conf on Distributed Computing Systems. Phoenix: IEEE Computer Society, 2001. 391-398.
  • 7D Ferraiolo, R Sandhu, S Gavrila et al. A proposed standard for role-based access control. NIST. 2000. http://csrc. hist. gov/rbae/.
  • 8D K Gifford, P Jouvelot, M A Sheldon et al. The research file systems. In: Proc of the 12th ACM SIGOPS Symposium on Operating Systems Principles. Pacific Grove, CA: ACM Press,1991. 16-25.
  • 9Yan Han,ACM SIGSOFT Software Engineering Notes,2000年,25卷,2期,64页
  • 10Dewan D,ACM Transactions Computer Human Interaction,1998年,5卷,1期,34页

共引文献196

同被引文献34

引证文献4

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部