作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2013, Vol. 39 ›› Issue (4): 180-183,189. doi: 10.3969/j.issn.1000-3428.2013.04.042

• 安全技术 • 上一篇    下一篇

基于XACML的EPCIS访问控制模型

李景峰,李云鹏   

  1. (解放军信息工程大学电子技术学院,郑州 450004)
  • 收稿日期:2012-05-14 出版日期:2013-04-15 发布日期:2013-04-12
  • 作者简介:李景峰(1977-),男,副教授、博士,主研方向:无线网络安全,装备系统工程;李云鹏,硕士研究生
  • 基金资助:
    河南省基础与前沿技术研究计划基金资助项目(122300410123);郑州市科技攻关基金资助项目(10PTGG340-4)

Access Control Model for EPCIS Based on XACML

LI Jing-feng, LI Yun-peng   

  1. (Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004, China)
  • Received:2012-05-14 Online:2013-04-15 Published:2013-04-12

摘要: 根据供应链系统对EPC信息服务(EPCIS)提出的访问控制需求,设计一种基于可扩展访问控制标记语言(XACML)的EPCIS访问控制模型。模型中的访问控制执行接口利用方法拦截技术实现对访问请求的拦截,并生成决策上下文对象。访问控制服务组件基于决策上下文对象中包含的用户、资源、环境和动作属性实现对访问请求的动态评估。安全通信组件利用安全性断言标记语言,结合缓存机制实现XACML授权请求/响应的实时传输。访问控制流程表明,该模型能够实现灵活的访问控制策略部署和管理,具有供应链产品信息访问控制的动态性、异构性等特点。

关键词: 电子产品码网络, EPC信息服务, 访问控制, 可扩展访问控制标记语言, 安全性断言标记语言, 供应链

Abstract: The special access control requirements of EPC Information Service(EPCIS) in the supply chains are analyzed, and an EPCIS access control model based on Extensible Access Control Markup Language(XACML) is presented. The access control execution interface in the model can intercept the access requests by using the method intercepting technology, and produce the corresponding judgment context. Based on the user property, resource property, environment property and action property, which are included into the judgment context, the access control service component can dynamically assess the access requests. The secure communication component can effectively provide the real-time transmission for XACML authorization request/response messages, by combining the Security Assertion Markup Language(SAML) and the caching mechanism. The access control workflow indicates that the model can implement the flexible and variable deployment and management of the access control strategies, which is well fit for implement highly dynamic and heterogeneous access control function for the product information in the supply chains.

Key words: Electronic Product Code(EPC) network, EPC Information Service(EPCIS), access control, Extensible Access Control Markup Language(XACML), Security Assertion Markup Language(SAML), supply chains

中图分类号: