摘要
访问控制策略是确定分布式聚合资源访问控制的关键。为了保证分布式系统下信息的安全交互和互操作,该文基于多维属性建立主体与客体的网络行为控制通用模型,刻画实体间授权关系,通过策略与规则扩展形式化框架;基于多维属性网络行为控制模型,对分布式系统中访问者访问Web服务的网络行为进行实例分析和模型应用;在实例化策略与规则描述中,提出了策略生成规则方法,给出了规则冲突与冗余的检测与消除方法。通过实例化应用分析表明:该模型与策略方法具有很强的普适性和可扩展性。
The key problem in network control strategies is to determine the access control policies for distributed aggregated resources. The security interactions and interoperability are analyzed here using a general network control model based on the multidimensional attributes of the network behavior to prescribe authorization relations between entities at the attribute level. An'example is given for a visitor accessing the Web service in a distributed system based on the general network control model. The security generation method proceeds from high level behavior control strategies to executable rules. The system is also able to detect and eliminate conflicts and redundancies. The method is easy to apply and has good scalability.
出处
《清华大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2013年第12期1682-1687,共6页
Journal of Tsinghua University(Science and Technology)
基金
国家"八六三"高技术项目(2011AA010703)
关键词
访问控制
控制策略
多维属性
规则
control
network control strategy
multidimensional attributes
firewall rules