摘要
针对移动节点的移动性和随机性,传统的身份认证和访问控制不能提供足够的安全保障,提出对移动节点进行风险评价.基于蜂窝历史访问信息评价信任风险,位置信息评价位置风险,时态信息评价时态风险,并提出使用CCRAA综合评判信任风险、位置风险和时态风险的综合风险,提高了移动节点访问行为的安全性,以及权限管理的灵活性,避免模糊综合评判因为权值分配带来的不确定性.最后,使用实例对CCRAA和模糊综合评判的风险评判过程进行了比较.
Because conventional identity authentication and access control cannot ensure sufficient security due to the mobility and ran- domness of mobile nodes (MNs) ,risk evaluation is performed on MNs. Based the cellular historical access information to evaluate the trust risk, the positional information to assess the positional risk and the temporal information to evaluate the temporal risk, and using CCRAA to integrate the trust, positional and temporal risks into the access risk, strengthening security in MN access behavior and flexibility in authority management, for avoiding the uncertainties that are present in such integrative methods as the overall fuzzy e- valuation due to assignment of the weights. Finally, an example is used to compare the risk evaluation process between CCRAA and Fuzzy Overall Evaluation.
出处
《小型微型计算机系统》
CSCD
北大核心
2014年第8期1794-1797,共4页
Journal of Chinese Computer Systems
基金
国家自然科学基金面上项目(61370073)资助
湖南省教育厅科技计划项目(11C0286)资助
关键词
移动节点
访问授权
位置时态
风险评判
模糊聚合
mobile nodes
access authorization
positional temporal
risk evaluation
fuzzy aggregation