摘要
综合基于角色的访问控制和信任管理的各自优势,通过引入信任级别概念,文章提出了一个适用于开放式环境的动态信任通用访问控制模型—DTMGAC(Generic Access Control Model Based on Dynamic Trust Management)。模型依据用户身份信任和信任的动态度量,由信任级对角色分配关系实施约束,通过信任级动态调整角色权限分配关系,实现对角色可信授权委托控制。该模型具有良好的自治特性,不仅能细化访问控制粒度,增强系统实用性,而且还能有效降低威胁风险。
A Generic Access Control Model Based on Dynamic Trust Management(DTMGAC) suitable for open network environments is presented which integrates the merits of both RBAC and trust management. It extends the conventional role based access control model with the notion of trust level. Users are assigned to trust levels instead of roles based on dynamically computing a number of factors like user credentials and user behavior history. This model could effectively control the permissions propagation of different sensitivity levels in roles based on the method of restricting privileges in a special trust level range. DTMGAC model is formallly specified and analyzed by automata syntax. This model could make the access control more precise and effectively reduce the threaten risk.
出处
《信息安全与通信保密》
2009年第9期103-106,109,共5页
Information Security and Communications Privacy
基金
国家"863"计划基金资助项目(2008AA01Z404)
国防预研基金资助项目(9140A26010306JB5201)
关键词
访问控制
模型规范
信任关系
行为信任
access control
model specification
trust realationship
trust management