摘要
在使用控制(usage control,UCON)核心模型UCONABC(usage control authorizations,obligations,conditions)中引入委托机制,对委托的粒度、深度、广度以及授权回收等问题进行研究,并通过划分主体属性,建立属性与权利的对应关系等方式,设计了新的带有委托授权特征的UCONABC模型,并给出两个具有委托授权特征的UCONABC子模型的形式化描述,最后,通过委托授权模型在数字资源访问控制中的一个应用实例,验证带有委托授权特征的UCONABC模型的有效性,并以此体现对于开放式环境中基于属主的委托授权问题的研究意义.
After the mechanism of delegation was introduced to the usage control authorizations,obligations,conditions(UCONABC) model,the problems of the delegation were studied in granularity,depth,breadth and authorization recycling.Moreover,according to the subject attribute,the modes of the relationship between attributes and rights were established and a new UCONABC model was designed with the characteristic of delegation.And the formal descriptions of two sub-model for UCONABC with the characteristic of delegation were given.Finally,the effectiveness of the new model was proved by its application in digital resource access control,which reflected the importance of the management of delegation based on the owner in the open system environment(OSE).
基金
安徽省高校自然科学研究项目(KJ2011Z063)资助
关键词
使用控制
委托授权
属性
授权回收
开放式环境
usage control
delegation
attribute
authorization recycling
open system environment