摘要
P2P具有无集中控制节点、节点对等自治和网络动态的特点,这些特点为实施访问控制带来很大的挑战,传统的访问控制技术不能很好地适应对等网环境。首先对现有的对等网环境中的访问控制技术进行研究,然后在基于信任模型的角色访问控制的基础上,针对无法区分通过信任模型计算出相同结果的用户的问题,提出了基于信任和属性的访问控制。基于信任和属性的访问控制引入资源属性和用户属性来分别描述资源和用户,依据用户属性、信任模型计算出的数值、环境属性和授权策略来建立用户角色指派关系,依据资源属性和授权策略来建立角色权限指派关系,从而解决基于信任模型的角色访问控制存在的问题。
Traditional access control models which are based on identity are not adaptive in P2P environments,which characterize non-centralization,autonomy and dynamic characteristic.We analyzed the access control issue in P2P envi-ronments.The existing trust-based role access control lacks measures to distinguish users whose results from a trust model are same.We proposed trust-attribute-based access control to deal with this problem.Trust-attribute-based ac-cess control describes users and resources using user attributes and resource attributes.The model builds user role as-signment using user attributes,the result from a trust model,environment attributes and authorization policy and builds role permission assignment using resource attributes and authorization policy.
出处
《计算机科学》
CSCD
北大核心
2011年第2期28-31,41,共5页
Computer Science
基金
国家自然科学基金(60903225
70971134)资助。