首页> 外文会议>International Conference on Information Science, Signal Processing and their Applications >Research of Access Control Policy Based on Context and Role for Web Service
【24h】

Research of Access Control Policy Based on Context and Role for Web Service

机译:基于Web服务的上下文和角色的访问控制策略研究

获取原文

摘要

The interacting entities in web service usually can’t be predetermined and may be in different security domains. To address the access authorization for unknown users across domain borders, access control of web service should be performed based on the domain-independent access control information but not the identities. In this paper, a context and role based access control policy model is proposed that can be appropriate for web service environment. The model is centered around the contexts to define and perform access control policies. It first bases the context of users to execute dynamic roles assignment, and then uses the contexts of environment and resource to constrain the authorization decision. We use Description Logic language to formalize the policy model. A series of access control policy axioms are defined and the Access Control Policy Knowledge Base is proposed that has the capacity of reasoning about the policies. Finally, the enforcement effect of access control policy is verified in Racer reasoning system, and the experiment result shows the feasibility and validity of the presented method.
机译:Web服务中的交互实体通常不能预先确定,并且可以在不同的安全域中。为了解决域边框的未知用户的访问授权,应基于域无关的访问控制信息但不是标识来执行Web服务的访问控制。在本文中,提出了一种上下文和基于访问控制策略模型,其可以适合Web服务环境。该模型围绕上下文居中,以定义和执行访问控制策略。它首先基于用户的上下文来执行动态角色分配,然后使用环境和资源的上下文来约束授权决策。我们使用描述逻辑语言来形式化策略模型。定义了一系列访问控制策略公理,提出了访问控制策略知识库,其具有对策略的推理能力。最后,在赛车推理系统中验证了访问控制策略的执法效果,实验结果表明了呈现的方法的可行性和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号