节点文献
基于角色和上下文的动态网格访问控制研究
Dynamic Role and Context-Based Access Control for Grid Applications
【摘要】 网格计算旨在使地理上分散的资源实现全面共享与协同工作,网格环境的异构、动态和多域的特点为网格的安全研究带来了新的挑战。近年来在网格访问控制方面做了大量研究,大多在一个相对静态的假设下,主要依靠主体的标识来实现访问控制,缺少基于上下文的访问控制来适合动态的网格环境。文章提出了一个基于角色和上下文的动态网格访问控制(RCBAC)模型,RCBAC 扩展了 RBAC 模型,增加了上下文约束。RCBAC 从网格应用环境中获取与安全相关的上下文信息来动态地改变用户的权限,同时保留了传统 RBAC 模型的优点,这一访问控制模型正在实践中实施。
【Abstract】 Grid computing is concerned with the sharing and coordinated use of diverse resources in distributed“virtual organizations”.The heterogeneous,dynamic and multi-domain nature of these environments introduces challenging se- curity issues.Despite the recent advances in access control approach applicable to grid computing,there remain issues that impede the development of effective access control models for Grid applications.Amongst them are the lack of con- text-aware models for access control,and reliance on identity or capability-based access control schemes.In this paper, we present an access control scheme that resolve these issues,and propose a Dynamic Role and Context-Based Access Control(RCBAC)framework which extends the RBAC with context constraints.The RCABC mechanisms dynamically grant and adapt permissions to users based on a set of contextual information collected from the system and user’s envi- ronments,while retaining the advantages of RBAC model.RCBAC model is being implemented in our experiment.
- 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2006年01期
- 【分类号】TP393.07
- 【被引频次】27
- 【下载频次】214