摘要
P2P系统的匿名性和动态性给其安全性和可靠性带来了挑战.并在很大程度上限制了P2P的大规模商业应用.本文提出了一种P2P环境下基于使用控制的动态访问控制模型PUCON,该模型改进了传统的访问控制模型不能很好地适应P2P网络环境的不足.该模型由认证、控制和更新三大模块组成,以访问监控器为执行部件,以混合方式管理属性,达到了持续性控制和属性动态更新目的.通过仿真实验,验证了本模型的安全性和有效性.
The anonymity and dynamics of the P2P network bring many security prob- lems to security and dependability of services offered by it, which seriously limit the large scale commercial applications of P2P. The traditional access control models and trust management models can not satisfy the P2P environment commendably. This paper proposes a dynamic access control model PUCON which based on usage control for P2P environment. In this model, access control policies are composed by authenticate, control, and update module, the reference monitor is used as enforcement component, attribute managed by mix types, then the decision continuity and attribute mutability are practical. Finally, a examination system is implemented to prove the security and feasibility of the proposed model.
出处
《华中师范大学学报(自然科学版)》
CAS
CSCD
北大核心
2011年第1期31-36,42,共7页
Journal of Central China Normal University:Natural Sciences
基金
江苏省高校自然科学基金资助(10KJD480003)
关键词
对等网络
访问控制
使用控制
peer to peer network
access control
usage control