期刊文献+

网格环境下基于属性的访问控制策略合成研究 被引量:5

Study on composing attribute-based access control policies in grid
下载PDF
导出
摘要 为了满足网格环境下资源聚合对访问控制策略合成的需求,达到建立统一的安全策略的目的,提出了一种扩展的基于属性的访问控制(ABAC)策略合成代数来实现安全策略的合成,该合成在策略表达式中引入了环境属性,并结合了一种新的策略合成算子实现访问控制策略的合成。用一个具体的策略合成案例展示了策略的合成,说明策略合成方法有良好的语义表达能力、灵活性以及可扩展性。 In order to meet the needs to composing access control policies by aggregation resources and achieve a unified security policy aim in grid,this paper proposed an extended composing algebra for ABAC policies to composing access control policies.It introduced the environment attribute in policy expression,and implemented composing access control policies with a new policy composition algebra.The policies composition with a specific case shows that this policies composition algebra provide a good semantic expression power,flexibility and scalability.
出处 《计算机应用研究》 CSCD 北大核心 2011年第7期2683-2686,共4页 Application Research of Computers
基金 重庆大学研究生科技创新基金资助项目(CDJXS10180013) 国家自然科学基金资助项目(60803027)
关键词 网格 访问控制 安全策略 属性 策略合成代数 grid access control security policy attribute policy composition algebra
  • 相关文献

参考文献7

  • 1倪文婷,郎波.网格计算中一种基于属性的访问控制方法[J].计算机应用研究,2010,27(2):699-703. 被引量:1
  • 2林莉,怀进鹏,李先贤.基于属性的访问控制策略合成代数[J].软件学报,2009,20(2):403-414. 被引量:41
  • 3BONATYI P, De CAPITANI Di VIMERCATI S SAMARATI P,et al. An algebra for composing access control policies[ J]. ACM Trans on Information and System Security, 2002,5 ( l ) : 1-35.
  • 4WIJESEKERA D, JAJODIA S. Apropositional policy algebras for access control[ J]. ACM Yrans on Information and System Security, 2003,6(2) :286-325.
  • 5BACKES M, DURMUTH M, STEINWANDT R. An "algebra for composing enterprise privacy policies [ C ]//Proc of the 9th European Symp on Research in Computer Security. Berlin: Springer-Verlag, 2004 : 33-52.
  • 6HU V C,FERRAIOLO D F,SCARFONE K. Access control policy combinations for the grid using the policy machine [ C ]//Proc of the 7th IEEE International Symp on Cluster Computing and the Grid. Washington : IEEE Computer Society,2007:225-232.
  • 7CHENG Xiang-ran, CHEN Xing-yuan, ZHANG Bin,et al. An algebra for composing access control policies in grid [ C ]//Proc of International Conference on Computational Intelligence and Security. 2009: 526-530.

二级参考文献8

  • 1HUAI Jinpeng HU Chunming LI Jianxin SUN Hailong WO Tianyu.CROWN:A service grid middleware with trust management mechanism[J].Science in China(Series F),2006,49(6):731-758. 被引量:8
  • 2ISO/IEC 10181-3, Information technology: open system interconnection security frameworks for open system: access control framework [ S]. Geneva: ISO/IEC,1996.
  • 3YUAN E, TONG J. Attribute based access control (ABAC) for Web services[ C]//Proc of IEEE International Conference on Web Services. Piscataway : IEEE Computer Society, 2005:561 - 569.
  • 4OASIS: eXtensible access control markup language (XACML) version 2.0 [ EB/OL ]. (2003-08 ) [ 2008-10-05 ]. http ://www. oasisopen. org/committees,/xacml/ .
  • 5LANG Bo, IAN F, FRANK S, et al. Attribute based access control for grid computing [ EB/OL]. (2006). Ftp. mcs. anl. gov/pub/tech_ reports/reports/P1367, pdf.
  • 6LANG Bo, LU You, LI Wei-qin. A flexible access control mechanism supporting large scale distributed collaboration [ C ]//Proc of the 8th International Workshop on CSCW in Design. 2004.
  • 7GT4.0 : Security : authorization framework [ EB/OL ]. ( 2004- 06 ) [ 2007-12 - 20 ]. http ://www. globus, org/toolkit/docs/4.0/security/ authzframe/.
  • 8DEMCHENKO Y, GOMMANS L, LAAT C de. Using SAML and XACML for complex resource previsioning in grid based applications [ C ]//Proc of IEEE Workshop on Policies for Distributed Systems and Networks. 2007 : 183-187.

共引文献40

同被引文献50

引证文献5

二级引证文献21

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部