期刊文献+

基于策略属性协商的云间组合服务访问控制机制

Access control mechanism for cloud composite service with policy attribute negotiation
下载PDF
导出
摘要 提出一种基于策略属性协商的云间组合服务访问控制机制.使用属性来表达服务组件之间的授权关系,能够满足云环境下动态、弹性、点对点的交互特点,该机制使用策略属性协商来实现访问控制的交互,减少了服务内安全信息的披露,有效地保护了用户隐私,实现了云组合服务内不同服务组件的策略对外一致性的访问控制表现.设计一种基于历史信息的策略协商算法,通过同步高频协商策略、存储历史协商信息、计算属性披露开销,来优化协商流程,提高交互效率.仿真实验验证了该机制的可行性及其运行效率. APoAN(access control mechanism based on policy attribute negotiation)was proposed for cloud composite servic.In APoAN,an authorization relation between service components was described at the attribute level that can meet the dynamic,flexible,point-to-point interaction characterisics in cloud environment.The mechanism used policy attribute negotiation to achieve interactive process of access control,which reduced the disclosure of security information within the service and effectively protected the user's privacy.The mechanism can ensure the consistent presentation of different service components policies in global composite service.A policy negotiation algorithm was designed based on historical information.The negotiation process was optimized and the efficiency of negotiation was improved by synchronizing high frequency negotiation policy,storing history information of negotiation and calculating the cost of attributes disclosure.Finally,the simulation results show the feasibility and efficiency of the proposed mechanism.
出处 《浙江大学学报(工学版)》 EI CAS CSCD 北大核心 2017年第12期2332-2340,共9页 Journal of Zhejiang University:Engineering Science
基金 国家"863"高技术研究发展计划资助项目(2015AA011705) 国家重点研发计划资助项目(2016YFB0501901 2015AA016006) 国家自然科学基金资助项目(61502531) 河南省自然科学基金资助项目(162300410334)
关键词 访问控制 策略协商 云服务 服务组合 基于属性的访问控制(ABAC) access control policy negotiation cloud service service composition attribute based access control(ABAC)
  • 相关文献

参考文献3

二级参考文献69

  • 1李建欣,怀进鹏,李先贤.自动信任协商研究[J].软件学报,2006,17(1):124-133. 被引量:52
  • 2WANG Xiaoming,ZHAO Zongtao.A Service Oriented Voting Authorization Model[J].Chinese Journal of Electronics,2006,15(1):37-40. 被引量:2
  • 3李建欣,怀进鹏.COTN:基于契约的信任协商系统[J].计算机学报,2006,29(8):1290-1300. 被引量:18
  • 4廖振松,金海,李赤松,邹德清.自动信任协商及其发展趋势[J].软件学报,2006,17(9):1933-1948. 被引量:52
  • 5HUAI Jinpeng HU Chunming LI Jianxin SUN Hailong WO Tianyu.CROWN:A service grid middleware with trust management mechanism[J].Science in China(Series F),2006,49(6):731-758. 被引量:8
  • 6M LeMay,O Fatemieh,C A Gunter.PolicyMorph:interactive policy transformations for a logical attribute-based access control framework[A].Proceedings of the 12th ACM Symposium on Access Control Models and Technologies[C].New York:ACM,2008.205-214.
  • 7V Kolovski,J Hendler,B Parsia.Analyzing web access control policies[A].Proceedings of the 16th International Conference on World Wide Web[C].New York:ACM,2007.677-686.
  • 8E Yuan,J Tong.Attributed based access control (ABAC) for web services[A].Proceedings of the IEEE International Conference on Web Services[C].Washington:IEEE Computer Society,2005.561-569.
  • 9C Ye,Z Wu,Y Fu.An attribute-based delegation model and its extension[J].Journal of Research and Practice in Information Technology,2006,38 (1):3-17.
  • 10J Michael,R Manoj.A contextual attribute-based access control model[A].Proceedings of 2006 Workshops on the Move to Meaningful Internet Systems[C].Berlin:Springer,2006.1996-2006.

共引文献116

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部