作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程

• 安全技术 • 上一篇    下一篇

基于属性的角色委派模型可达性推理方法研究

任志宇1,2,3,陈性元1,2,马军强1   

  1. (1. 解放军信息工程大学四院,郑州450001;2. 河南省信息安全重点实验室,郑州450004;3. 数学工程与先进计算国家重点实验室,郑州450001)
  • 收稿日期:2013-09-09 出版日期:2014-09-15 发布日期:2014-09-12
  • 作者简介:任志宇(1974 - ),女,博士研究生,主研方向:信息安全,访问控制,授权管理;陈性元,教授、博士、博士生导师;马军强,副 教授。
  • 基金资助:
    国家“973”计划基金资助项目(2011CB311801);河南省科技创新人才计划基金资助项目(114200510001)。

Research on Reachability Reasoning Method for Attribute-based Role Assignment Model

REN Zhi-yu  1,2,3,CHEN Xing-yuan  1,2,MA Jun-qiang  1   

  1. (1. The 4th Institute,PLA Information Engineering University,Zhengzhou 450001,China;2. Henan Province Key Laboratory of Information Security,Zhengzhou 450004,China;3.State Key Laboratory of Mathematical Engineering and Advanced Computing,Zhengzhou 450001,China)
  • Received:2013-09-09 Online:2014-09-15 Published:2014-09-12

摘要: 提出基于属性的角色委派模型,通过引入属性扩展授权管理策略的表达能力,并采用描述逻辑定义模型的概念及其关系。为解决分布式环境下授权管理策略检测困难的问题,对模型的用户-角色可达性问题进行定义和分析,采用SWRL 描述推理规则,利用推理引擎实现用户-角色可达性的自动推理,并通过应用实例对推理方法的正确性和可行性进行验证。实验结果表明,针对某一策略进行推理时所需的时间随策略数量的增加上升平缓,因此,该推理方法适用于授权管理策略的自动检测,可有效避免因策略执行结果不直观而引发的安全隐患,为授权管理模型的安全应用提供支撑。

关键词: 属性, 角色委派, 可达性, 推理, 基于角色的访问控制, 描述逻辑

Abstract: By introducing attributes to provide richer semantics for Role-based Access Control(RBAC) management policy,the attribute-based role assignment model is proposed. It is formalized by description logic,including concepts and relations. In order to resolve the difficulty of privilge management policy detection in distributed environment,the userrole reachability analysis problem is defined and analyzed. The inference rules are described by SWRL,and imported into the inference engine to realize automated reasoning. Application example shows that the reasoning method is correct and feasible. Experimental result shows that the reasoning time rises slowly by the count of policy. So the reasoning method is practical for the automatic policy detection. It can avoid potential security problems,and offer a basis for the safe application of the privilge management model.

Key words: attribute, role assignment, reachability, reasoning, Role-based Access Control(RBAC), description logic

中图分类号: