节点文献

基于描述逻辑的RB-RBAC授权规则冲突检测方法

Research on Description Logic Based Conflict Detection Methods for RB-RBAC Model

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 于海波车海燕金淳兆

【Author】 YU Hai-Bo CHE Hai-Yan JIN Chun-Zhao (College of Computer Science and Technology, Jilin University, Changchun 130012)

【机构】 吉林大学计算机科学与技术学院吉林大学计算机科学与技术学院 长春130012长春130012

【摘要】 RB-RBAC(Rule-BasedRBAC)模型克服了RBAC模型的一些局限,提供了基于用户属性自动指派角色的机制。为了检测RB-RBAC模型的策略冲突,提出了一种基于描述逻辑的RB-RBAC模型的形式化方法,在此基础上提出了一种检测有关规则间冲突的方法、一种发现无关规则间冲突的方法和在授权规则集合中检测不同类型冲突的方法,可以根据具体情况选择不同的方法以提高效率。并给出了一种简单的冲突消解方法。

【Abstract】 RB-RBAC(Rule-Based RBAC)provides the mechanism to dynamically assign users to roles based on a finite set of authorization rules defined by the enterprise’s security policy. These rules may have conflict due to negative authorization. We propose a formalization of RB-RBAC by description logic language ALC, and then represent conflict detection method based on knowledge base consistency. Some different methods are suggested to detect conflict among related rules and that among unrelated rules, and they may cooperatively work in one system to provide more efficient detecting service. We also give a simple method to rewrite conflict rules for eliminating policy conflict.

【基金】 国家自然科学基金项目(60173006);国家高技术研究发展计划项目(2003AA118020);“吉林大学‘985’工程”项目。
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2006年10期
  • 【分类号】TP309
  • 【被引频次】10
  • 【下载频次】222
节点文献中: