Secure interaction and interoperability between two or more administrative domains is a major concern. The IRBAC 2000 model accomplishes secure interaction and interoperability by flexibly dynamic inter-domain role tr...Secure interaction and interoperability between two or more administrative domains is a major concern. The IRBAC 2000 model accomplishes secure interaction and interoperability by flexibly dynamic inter-domain role translations. Associations are the key element of the IRBAC 2000 model, which have a great impact on security and efficiency of dynamic role translations. Therefore, it is a crucial problem how to manage the associations in the IRBAC 2000 model. There are two cases under which some matters will emerge. One is where conflicting associations may result in a security hazard. Another is where redundant associations may reduce the efficiency of dynamic role translations and increase the difficulty of management of associations. The formal definitions on conflicting associations and redundant associations are given, and the methods are discusses to judge whether there are conflicting associations or redundant associations in IRBAC 2000 model. The protective mechanism is presented, which utilizes prerequisite conditions to prevent conflicting or redundant associations from appearing in IRBAC 2000 model.展开更多
基金Supported bythe Scientific Research Foundation ofHunan Provincial Education Department (03C500)
文摘Secure interaction and interoperability between two or more administrative domains is a major concern. The IRBAC 2000 model accomplishes secure interaction and interoperability by flexibly dynamic inter-domain role translations. Associations are the key element of the IRBAC 2000 model, which have a great impact on security and efficiency of dynamic role translations. Therefore, it is a crucial problem how to manage the associations in the IRBAC 2000 model. There are two cases under which some matters will emerge. One is where conflicting associations may result in a security hazard. Another is where redundant associations may reduce the efficiency of dynamic role translations and increase the difficulty of management of associations. The formal definitions on conflicting associations and redundant associations are given, and the methods are discusses to judge whether there are conflicting associations or redundant associations in IRBAC 2000 model. The protective mechanism is presented, which utilizes prerequisite conditions to prevent conflicting or redundant associations from appearing in IRBAC 2000 model.