节点文献
公共对象请求代理体系结构安全中的访问控制策略研究与实现
Research and Implementation on Access Control Policy in CORBA Security
【作者】 熊晓萍;
【作者基本信息】 华中科技大学 , 计算机系统结构, 2004, 硕士
【摘要】 随着公共对象请求代理体系结构CORBA(Common Object Request Broker Architecture)的广泛应用,CORBA安全面临前所未有的挑战。特别是CORBA系统中众多对象的访问控制问题,一直是构建高性能安全环境的瓶颈。基于角色访问控制RBAC(Role-Based Access Control)技术作为一种先进的访问控制手段,其优势在于:根据安全需求划分出不同的角色执行特定的任务,从而实现用户与权限的分离,因此可以作为CORBA安全中复杂访问控制的解决之道。在分析RBAC与CORBA融合可行性的基础之上,结合CORBA本身安全服务提供的支持,给出了CORBA基于角色访问控制系统RICS(RBAC In CORBA System)的总体框架,并针对其中的核心部分展开详细设计:借鉴基于X.509标准的公钥基础设施PKIX(Public Key Infrastructure based on X.509)身份认证框架来完成访问控制前的主体身份认证功能;采用CORBA拦截器技术来保证RBAC与CORBA融合之后实施访问控制的安全性;通过策略工厂管理策略对象和RBAC配置,实现了CORBA中访问控制策略的集中化管理;依靠定制的对象调用关系图与策略工厂,优化了访问决策器进行决策时所需的步骤。总之,RICS的设计充分考虑到了访问控制过程中的可配置性和可扩展性。基于RICS的总体设计,通过选择恰当的拦截点,论述了访问控制拦截器实现访问控制的三个基本阶段:创建凭证、绑定和访问决策,并给出了一个CORBA应用实例——项目管理系统PMS(Projects Management System)。访问控制拦截器能够保证任何请求在到达服务对象之前进行访问控制。PMS应用结果表明,借助CORBA的对象通信机制,RICS实现了主体角色的自动更新,使得访问控制策略更加灵活有效,能够适应随时发生变化的RBAC配置。
【Abstract】 With the wide use of CORBA(Common Object Request Broker Architecture), CORBA security is confronted with a real challenge. Especially the access control of numerous objects in CORBA is the bottleneck to construct the high-powered environment of security. As an advanced means of access control, the strongpoint of RBAC(Role-Based Access Control) is making off the roles which separates the users from the permissions according to the security requirements for the relevant assignments. Therefore RBAC can be used to solve the complicated access control in CORBA security.Based on analyzing the feasibility of implementing RBAC into CORBA, the system architecture of RICS(RBAC In CORBA System) is proposed with the support offered by CORBA security services. And the detail designs for the key components are followed. The frame of PKIX(Public Key Infrastructure based on X.509) for identity authentication is responsible for the principal authentication. The interceptors in CORBA guarantee the security to the access control after implementing RBAC into CORBA. Policy Factory is designed to manage the policy objects and the configurations of RBAC, which achieves the central management of access control policies. The steps for access decision are optimized by policy factory and the tailored figure of invoking objects. In conclusion, the design of RICS is in view of being configurable and extensible.The process of access control actualized by the interceptors falls into three successive phases of creating the credential, binding and access decision based on RICS and the suitable points to intercept. Then the CORBA application example of PMS(Projects Management System) is presented. The interceptor can ensure that access control will occur before any request gets to the server.The result of implementing PMS proves that RICS realizes the automatic role <WP=5>activation by the objects communication. That makes the access control policies more flexible and effective. The whole system is adaptable to the frequently changed configuration of RBAC.
【Key words】 Common Object Request Broker Architecture; Role-Based Access Control; Interceptor; Access Decision; Policy Factory;
- 【网络出版投稿人】 华中科技大学 【网络出版年期】2005年 02期
- 【分类号】TP393.08
- 【被引频次】2
- 【下载频次】83