节点文献
基于描述逻辑的RB-RBAC授权规则冲突检测方法
Research on Description Logic Based Conflict Detection Methods for RB-RBAC Model
【摘要】 RB-RBAC(Rule-BasedRBAC)模型克服了RBAC模型的一些局限,提供了基于用户属性自动指派角色的机制。为了检测RB-RBAC模型的策略冲突,提出了一种基于描述逻辑的RB-RBAC模型的形式化方法,在此基础上提出了一种检测有关规则间冲突的方法、一种发现无关规则间冲突的方法和在授权规则集合中检测不同类型冲突的方法,可以根据具体情况选择不同的方法以提高效率。并给出了一种简单的冲突消解方法。
【Abstract】 RB-RBAC(Rule-Based RBAC)provides the mechanism to dynamically assign users to roles based on a finite set of authorization rules defined by the enterprise’s security policy. These rules may have conflict due to negative authorization. We propose a formalization of RB-RBAC by description logic language ALC, and then represent conflict detection method based on knowledge base consistency. Some different methods are suggested to detect conflict among related rules and that among unrelated rules, and they may cooperatively work in one system to provide more efficient detecting service. We also give a simple method to rewrite conflict rules for eliminating policy conflict.
【Key words】 RB-RBAC; Description logic; Authorization rule; Policy conflict; Conflict detection;
- 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2006年10期
- 【分类号】TP309
- 【被引频次】10
- 【下载频次】222