节点文献

访问控制策略应用研究与实现

Application Research and Implementation of Access Control Policy

【作者】 屈松

【导师】 陈林; 罗琳;

【作者基本信息】 重庆大学 , 软件工程, 2008, 硕士

【摘要】 随着企业信息化程度的提高,信息安全成为企业必须重视的问题。企业级应用软件系统的权限管理功能不完善极大的威胁着企业的信息安全。访问控制是权限管理的重要组成部分,它在信息系统中用来确保只有授权人员才能访问敏感信息。对访问控制技术和系统实现进行研究具有非常重要的理论和实用价值。XACML(eXtensible Access Control Markup Language)是OASIS制定的用于访问控制策略的开放标准。与以往的策略描述语言相比,XACML基于XML语言,既具有能够同时被人和计算机识别的特点,也具有访问目标(Target)、主体(Subject)、操作(Action)以及规则(Rule)等其他策略描述语言相同的要素。RDF是W3C推荐的描述和交换元数据的框架,它是处理元数据的基础。RDF(Resource DescriptionFramework)的设计目标是定义一种描述资源的机制,该机制不是假设在某个特定的应用领域,也没有定义在任何应用领域的语义。本文的研究对访问控制策略的描述引入语义技术进行了尝试。论文首先对XACML和RDF的产生背景、各自的适用领域进行了介绍。然后结合RDF技术,提出了使用RDF来描述XACML访问控制策略的模型。XACML的格式相对而言较为复杂、冗长、不便于系统管理人员理解,基于语义描述的访问控制策略利用了语义技术具有一定的查询推理能力的优点,能十分方便地通过语义查询和XSLT转换为XACML访问控制策略。作者对耶鲁大学提出的开源单点登录系统CAS(Central Authentication Services)进行了扩展,利用提出的模型来实现用户的单点登录(single sign-on)。系统管理员只需要维护基础数据和访问控制策略就可以实现访问控制,减轻了系统维护的难度。由于RDF和XACML都是标准化组织制定的开放标准,标准的制定具有连续性,CAS的开发工作也越来越向遵守技术标准的方向靠近,支持的开放标准越来越多。本文的研究和实现对访问控制和单点登录的工程实践提供了一种有效的思路和方法。

【Abstract】 With the penetration of IT in enterprises, the security of information system has become as issue of great importance. One threat to the information security comes from the deficiency in the administrative function of access control in the applied software used in enterprises. Access control, as a crucial part of permissive security, ensures that only the authorized personnel are capable of accessing sensitive information. The research on access control technology and its systematic implementation has a very important theoretical and practical value.XACML is an open specification designed by OASIS for accessing policies management. Comparing to other existing standard access control language, XML-based XACML can be identified by both human-being and computer, while having the functions, included in other policy descriptive languages, of accessing Target, Subject, Action and Rule. RDF recommended by W3C for describing and exchanging is the foundation of processing metadata. The purpose of designing RDF is to define a mechanism of resource description, instead of assuming certain practical environment or defining semantics applied to any practical field.The present research intends to apply semantics technology to access control policy expression. The author starts with in the background of how the XACML and RDF came into being and their respective application field. Then, based on the combination of RDF technology, the author suggests a model using RDF to express XACML access control policy. The syntax of XACML is comparatively complex and interminable for system administrators to comprehend. Using the semantics technology, the semantics-based access control policy, to a certain degree, has the advantages of being capable of querying and illation. It can also be converted into XACML expediently by means of querying and XSLT. The author extends the CAS originally developed by Yale University, and implements single sign-on with the suggest model. Access control can be implemented by the system administrator simply through maintaining the basic data and access control policy. This reduces the difficulty of system maintenance.RDF and XACML are both open specification established in succession by organization for standardization, and the exploitation practice of CAS is orienting to the technical standard, begin supportive to an increasing amount of open specification. The research and implementation of access control and single sign-on in this thesis provides engineering practice with an effective measure.

【关键词】 RDFXACML访问控制
【Key words】 RDFXACMLAccess Control
  • 【网络出版投稿人】 重庆大学
  • 【网络出版年期】2009年 06期
  • 【分类号】TP393.08
  • 【被引频次】1
  • 【下载频次】133
节点文献中: