节点文献

基于角色的信息网格访问控制的研究

Research on Role-Based Access Control in Information Grid

【作者】 邵桂伟

【导师】 杨善林;

【作者基本信息】 合肥工业大学 , 计算机应用与技术, 2006, 硕士

【摘要】 访问控制是信息网格安全机制的重要方面,它影响到网格系统中用户的操作行为。基于角色的访问控制(RBAC)是访问控制中常用的一种机制,RBAC不仅能显著增强访问控制能力,同时还会降低授权管理的复杂性,因而成为当前访问控制,尤其是信息网格中访问控制的研究热点。 信息网格是利用网格技术实现信息的共享、管理和提供信息服务的分布的信息系统,它由多个组织和个人相互共享信息,从而为网格用户提供更丰富的信息服务。然而,信息网格这种多管理域的特点使信息网格环境中的访问控制变得更为复杂,难以满足高效访问控制的要求。 信息网格跨管理域的访问控制涉及权限授予、验证和私有权限问题2个方面,也即本文的研究重点。域信任模式、信任第三方的授权认证机制、用户映射或者权限关系映射机制是目前解决跨管理域授权验证问题的方法,但它们分别具有管理开销大、不够灵活和实现困难等不足。本文通过对信息网格特点和RBAC模型进行分析、总结多管理域访问控制在RBAC机制中存在的问题,提出一种权限预先分配和两次验证的访问控制方法,从而提高了访问控制效率;目前解决私有权限问题的方法是使用私有角色和深度指示符这两种解决方法,通过分析得出这两种方法分别存在角色膨胀和组合爆炸的缺点,本文引入权限传播深度,提出了一种带有权限传播深度的解决方法,建立了ex-RBAC模型,该模型能够减少角色数量、降低管理复杂度,同时实现信息网格中跨管理域的权限私有化。 本文的研究工作改善了信息网格跨管理域的访问控制能力和效率,为RBAC在信息网格环境下的应用提供了有用的参考。

【Abstract】 Access control is a very important aspect in security of information grid,which affects the operation of users in grid system.Role-Based Access Control(RBAC)is an usual mechanism in accessing control,which can not only enhance access control capability but also reduce the complexity of authorization management effectively.It has been a hotspot of access control,especially in information grid accessing control.The information grid is a distributed information system,which use grid technology to implement the sharing and management of information and provide of information service,and information grid can sharing informations by many organizations and individuals,and provide users in grid system of much richer information service.However,the character that information grid has multi-manage domain makes access control in information grid condition more difficult,and are difficult to meet the requirements of efficient access control.The access control work among manage domain in information grid refers to authorization,validation and private privilege,which is the research points of this dissertation.The domain credible mechanism,the authorization and validation mechanism when trusting the third point and the user-privilege relation mapping mechanism are recently used in resolve the problem of authorization and validation among manage domain,but they have the disadvantages of expensive managing, unagilitive and difficult to achieve.This dissertation present a way of authorizing privilege beforehand and validating twice basing on analyzing characters of information grid and RBAC summarizing the problems in multi-manage domain accessing control,which can give high and efficient service in access control. We also analyses two present resolvations that use private roles and deepness fist notes ,from which we then know they can result in role inflate and compages explosion. Then we present a new resolvation with privilege transmit deepness, design an ex-RBAC model to resolve private privilege based on RBAC model,which can reduce the quantity of roles,play down the complexity of management and make the privilege private among manage domain in information grid.The Work has improved on the capability of access control among manage domain in information grid, and can be used for reference by their practical application, especially in grid environment.

  • 【分类号】TP393.08
  • 【被引频次】8
  • 【下载频次】152
节点文献中: