期刊文献+

基于组织的四层访问控制模型跨域访问过程中虚拟岗位构建方法 被引量:1

Construction method of virtual position in process of cross-domain access control based on organization based 4 levels access control model
下载PDF
导出
摘要 对于基于组织的四层访问控制(OB4LAC)模型在跨域访问控制过程中如何依据外域用户的申请权限集构建本域内虚拟岗位的问题,提出基于如下三阶段的处理流程,包括申请权限集与角色集的匹配搜索阶段、角色集职责分离(SoD)约束和激活约束判断阶段以及虚拟岗位的生成和撤销阶段。针对申请权限集与角色集的匹配搜索阶段,分别给出了面向完全匹配、可用性优先匹配和最小特权优先匹配的搜索算法;针对角色集SoD约束和激活约束判断阶段,则通过定义SoD约束矩阵(SODM)、非连通继承关系矩阵(AIM)和基数约束矩阵(CCM)以及对应的约束判断流程予以解决;针对虚拟岗位的生成和撤销阶段,给出了完成这一过程所需的管理函数。通过上述具体处理流程和实现算法,很好地解决了OB4LAC模型跨域访问过程中虚拟岗位的构建问题。 For the problems of Organization Based 4 Levels Access Control (OB4LAC) model on how to build the virtual positions based on the requested permission sets from users in other domain, this paper proposed a detailed process based on the following three stages, which are the searching stage of the role sets based on the required permission, the determining stage of Separation of Duty (SoD) and activating constraints, the creation and revoke stage of virtual position. Aiming to the searching stage of the role sets based on the required permission, the authors gave three searching algorithms that match three different cases respectively, which are complete matching, available matching and least privilege matching; for the determining stage of SoD and activating constraints, the authors defines three kinds of matrixes which are Separate of Duty Matrix (SODM), Cardinality Constraint Matrix (CCM) and Anti-connection Inherit Matrix (AIM), then based on those matrixes and corresponding process to solve these problems of constraints; aiming to the creation and revoke stage of virtual position, this paper gave the management functions required for completing the process. Through these specific processes and realization algorithms, the authors resolved the problems of building the virtual positions in multi-domain environment for OB4LAC model.
出处 《计算机应用》 CSCD 北大核心 2014年第8期2345-2349,共5页 journal of Computer Applications
基金 国家自然科学基金资助重点项目(91024029) 中国博士后面上资助项目(2013M540273)
关键词 基于组织的四层访问控制模型 跨域访问 多域 虚拟岗位构建 权限管理 信息安全 Organization Based 4 Levels Access Control (OB4LAC) model cross-domain access muhi-domains construction of virtual position authorization management information security
  • 相关文献

参考文献11

  • 1SHAFIQ B,JOSHI J B D,BERTINO E,et al.Secure interoperation in a multi-domain environment employing RBAC policies [J].IEEE Transactions on Knowledge and Data Engineering,2005,17(11):1557-1577.
  • 2刘猛,王轩,黄荷娇,赵海楠,张加佳.基于Petri网的IRBAC 2000域间动态转换SMER约束违反检测[J].计算机研究与发展,2012,49(9):1991-1998. 被引量:3
  • 3廖俊国,洪帆,朱贤,肖海军.多域间动态角色转换的职责分离[J].计算机研究与发展,2006,43(6):1065-1070. 被引量:14
  • 4LIU S,HUANG H.Role-based access control for distributed cooperation environment [C]// Proceedings of 2009 International Conference on Computational Intelligence and Security.Washington,DC:IEEE Computer Society,2009:455-459.
  • 5MA M,WOODHEAD S.Constraint enabled distributed RBAC for subscription-based remote network services [C]// Proceedings of the Sixth IEEE International Conference on Computer and Information Technology.Washington,DC:IEEE Computer Society,2006:1-6.
  • 6PENG Y,JU H,SONG Y,et al.OB4LAC:an organization-based access control model for e-government system [J].Applied Mathematics and Information Science,2014,8(3):1467-1474.
  • 7李凤华,苏铓,史国振,马建峰.访问控制模型研究进展及发展趋势[J].电子学报,2012,40(4):805-813. 被引量:127
  • 8RUSSELLO G,DULAY N.xDUCON:coordinating usage control policies in distributed domains [C]// Proceedings of the Third International Conference on Network and System Security.Washington,DC:IEEE Computer Society,2009:246-253.
  • 9ZHANG G,GONG W,TIAN J.The research of cross-domain usage control model in Web services [C]// Proceedings of the Second International Conference on e-Business and Information System Security.Piscataway:IEEE Press,2010:1-5.
  • 10DAI X,CHEN X,WANG Y,et al.An improved state transition-based security policy conflict detection algorithm [C]// Proceedings of the 2010 International Conference on Computational and Information Sciences.Chengdu:[s.n.],2010:609-612.

二级参考文献95

共引文献210

同被引文献9

引证文献1

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部