摘要
访问控制模型是信息安全领域研究的重点之一 .现有文献中可以见到许多访问控制模型 ,但其只能依据已有的事实由授权系统单方面对授权请求进行判定处理 ,不适合电子商务环境下根据用户对未来可满足条件的承诺进行交互式访问授权的需要 .提出了新的基于承诺 担保的访问控制模型 (PABAC)以满足上述访问控制需要 .讨论了模型体系结构 ,承诺担保机制 ,授权职责分离以及访问控制 .
The research of access control model is a topic of information security area.There are many access control models in existing literatures,but they process the access requests only depending on existing conditions by themselves.Therefore they are not able to meet the need that authorization process must interact with users and that user's promises of the future actions are authorization conditions under electronic commerce environment.A promise assurance based access control model (PABAC) is presented to achieve the above access control need.Its architecture,promise & assurance mechanism, separation of duties of authorization and access control are discussed.The experimental results express its validity.
出处
《电子学报》
EI
CAS
CSCD
北大核心
2003年第8期1150-1154,共5页
Acta Electronica Sinica
基金
国家自然科学基金 (No .90 2 0 4 0 1 2 )
国家"863"计划 (No.2 0 0 2AA1 4 30 2 1 )
关键词
访问控制
交互式授权
承诺
担保
职责分离
access control
interacting authorization
promise
assurance
separation of duty