摘要
传统自主访问控制(DAC)不具有时间敏感性,也不支持权限委托策略,这使得DAC很难满足对时间敏感的需求,而且对授出权限使用的不可控也可能造成权限滥用而带来安全隐患。提出了带周期时间特性的自主访问控制委托树模型(PDACDTM)。PDACDTM不仅在DAC中引入了周期时间、访问持续时间、访问次数和时序依赖来限制主体对客体的访问,而且在权限委托方面提出了委托树模型。该委托树模型通过委托深度和委托广度来限制委托权限的传播,同时还支持复合权限委托。PDACDTM以树形结构刻画了委托权限的传播,使得委托关系的处理更为明确、完备,也更加灵活且易维护。
Traditional Discretionary Access Control(DAC) is not time-sensitive and doesn't support the policy of permission delegation yet, which makes DAC difficult to meet the demand of time-sensitivity, and the using of granted permission with out control would bring risk by permission abuse.Therefore, a delegation tree model for DAC with periodicity constraints and time characters (PDACDTM) is proposed in this paper.PDACDTM not only introduces periodic time, durative access time,visits and timing-dependent to restrict subject's accessing to object,but also puts forward a delegation tree model in permission delegation.The delegation tree model restricts the propagation of permission by depth and width,in addition it supports the delegation of complex permissions.PDACDTM uses the structure tree to depict the spread of delegation permissions,it makes the relationship of delegation clearer, more comprehensive,more flexible and easier to be maintained.
出处
《计算机工程与应用》
CSCD
北大核心
2011年第6期93-98,180,共7页
Computer Engineering and Applications
基金
四川省科技厅项目(No.2008JY0105-2)
四川省教育厅项目(No.07ZA091)
关键词
自主访问控制
周期限制
委托树
discretionary access control
periodicity constraints
delegation tree