摘要
网格计算作为一种新的分布式计算模型,具有分布式、异构和动态变化等特性,若要在网格中实现资源共享的目的,资源的访问控制是首当其冲需要解决的问题。网格的访问控制是建立在现有的基于角色访问控制系统之上的,但是由于网格跨越多个不同的地点和不同的自治域,每个域的访问控制策略和需求可能相差甚远,这使得资源的访问控制更加复杂,如用户-角色的指派和映射。文章在现有的GSI改进授权模型中,用属性对角色进行了扩展,可实现更灵活、动态和细粒度的访问控制。
As a new distributed computing model,grid computing has the features of distributed,heterogeneous and dynamic change.If we want to realize resource sharing in the net,access control of resources is the most important problem.The resource sharing is established on the basic of the role-based access control system,but due to the different spots and different autonomous area,the access control policy is far away from the demand,it makes access control of resources more complicated,such as user-role assignment and mapping difficulty.In the GSI improved authorization model,attributes,extending from roles,can make up those shortcomings of RBAC,and also make access control more flexible,dynamic and fine-grained.
出处
《企业技术开发》
2010年第8期1-3,共3页
Technological Development of Enterprise
基金
华北电力大学青年教师科研基金资助(200911018)
关键词
网格计算
授权
GSI
角色
属性
grid computing
authorization
GSI
role
attribute