Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2010, Vol. 36 ›› Issue (18): 135-137. doi: 10.3969/j.issn.1000-3428.2010.18.046

• Networks and Communications • Previous Articles     Next Articles

Research on RBAC Policy Conflict and Its Detection Algorithm

CHENG Xiang-ran, CHEN Xing-yuan, ZHANG Bin, YANG Yan   

  1. (Electric Technology Institute, PLA Information Engineering University, Zhengzhou 450004, China)
  • Online:2010-09-20 Published:2010-09-30

RBAC策略冲突及其检测算法的研究

程相然,陈性元,张 斌,杨 艳   

  1. (解放军信息工程大学电子技术学院,郑州 450004)
  • 作者简介:程相然(1984-),男,硕士研究生,主研方向:网络安全;陈性元,教授、博士、博士生导师;张 斌,副教授、博士;杨 艳,讲师、硕士
  • 基金资助:
    国家“863”计划基金资助项目(2006AA01Z457, 2009AA 01Z438)

Abstract: With respect to conflict problems raised when implementing security principals such as separation of duty, least privilege in RBAC, this paper formalizes five RBAC policy conflict types, discusses causing reasons, and proposes a conflict detecting algorithm as well as simulation results, which can effectively detect conflicts defined in this paper. The work in this paper provides the basis for implementation for RBAC conflict detection.

Key words: RBAC policy, policy conflict, detection algorithm

摘要: 针对RBAC模型在实施职责分离、最小特权等安全原则时引起的冲突问题,形式化定义5种RBAC策略冲突类型,分析策略冲突产生的原因,提出一种完整的策略冲突检测算法并进行仿真测试。结果表明,该算法能够有效检测定义的各类策略冲突,为RBAC策略冲突检测实施提供基础。

关键词: RBAC策略, 策略冲突, 检测算法

CLC Number: