作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (20): 155-156. doi: 10.3969/j.issn.1000-3428.2006.20.056

• 安全技术 • 上一篇    下一篇

PMI中访问控制策略和实现机制的改进

李 真,张彩明,刘 颖   

  1. (山东经济学院计算机科学与技术系,济南 250014)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-10-20 发布日期:2006-10-20

Improvement of Access Control Policy and Realization Mechanism in PMI

LI Zhen, ZHANG Caiming, LIU Ying   

  1. (Department of Computer Science and Technology, Shandong Economic University, Jinan 250014)
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-10-20 Published:2006-10-20

摘要: :授权管理基础设施PMI是目前网络安全领域中的研究热点,如何提高PMI的系统效率以及如何标准化授权策略是当前遇到的主要问题。该文提出了一种基于条件的访问控制策略,结合XACML和J2EE的相关技术对策略的实现机制进行了改进,实现了一个基于该策略模型的PMI系统。该系统可有效地解决上述问题,给用户提供了更方便的权限管理和更细粒度的访问控制。

关键词: 授权管理基础设施, 可扩展访问控制标记语言, 访问控制, 策略

Abstract: Privilege management infrastructure is the research hotspot in the field of network security at present. How to improve the PMI system’s efficiency and how to standardize the access control policies are the main questions now. A condition based on access control policy and its implementation mechanism is improved by using XACML technology. Combined with J2EE technology, a PMI system based on the policy model is designed and implemented. The improved system resolves the questions above, provides convenient privilege management and fine-grained access control.

Key words: Privilege management infrastructure (PMI), Extensible access control markup language(XACML), Access control, Policy