摘要
Chinese Wall下的委托要求委托过程不但满足常见的委托约束条件外,还需要满足Chinese Wall Security Policy(CWSP)。现有的委托模型很少关注CWSP下的委托。分析了CWSP下委托的需求和特殊性。在对现有委托模型扩充的基础上,定义了冲突角色和角色激活历史来体现CWSP,给出了CWSP下进行委托需要满足的关系。提出了基于角色的CWSP下委托的方法与步骤。给出了系统实现框架和主要算法。
Delegation with "Chinese Wall" must satisfy not only regular delegation constraints,but Chinese Wall Security Policy (CWSP) as well.Existing delegation models pay little attentions to this field.This paper analyzes requirements and specificities of delegation with CWSP.Based on the extension of existing delegation models, this paper defines conflict role and role activa- tion history to describe CWSP, and gives relations to restrict delegation with CWSP.Methods and steps of delegation are proposed with CWSP based on role.This paper proposes implementation architecture and some main algorithms.
出处
《计算机工程与应用》
CSCD
北大核心
2011年第29期121-123,167,共4页
Computer Engineering and Applications
基金
国家自然科学基金(the National Natural Science Foundation of China under Grant No.60803027)
重庆市自然科学基金(CSTC
No.2008BB2320)
关键词
角色访问控制
委托
“中国墙”安全策略
role based access control
delegation
Chinese Wall Security Policy(CWSP)