基于隐藏证书的XACML访问控制扩展模型  被引量:2

AN EXTENDED XACML ACCESS CONTROL MODEL BASED ON HIDDEN CREDENTIAL

在线阅读下载全文

作  者:葛维进[1] 胡晓惠[1] 邓勇[1] 

机构地区:[1]中国科学院软件研究所,北京100190

出  处:《计算机应用与软件》2011年第3期265-268,共4页Computer Applications and Software

摘  要:XACML访问控制模型在SOA体系中,属于最新最先进的访问控制模型,但它却没有涉及对敏感属性及敏感策略的保护,这限制了该标准的推广价值。针对这一问题,提出了利用隐藏证书技术来扩展XACML访问控制模型,以提供对交互双方敏感属性及策略的保护,从而实现了基于XACML访问控制模型的自动信任协商。描述了如何使用XACML标准进行敏感策略的组织方式及方法,分析了扩展模型的安全性,证明了扩展模型可以抵御各类常规的分布式攻击。The access control model presented with eXtensible Access Control Markup Language(XACML) is the latest and most advanced access control model in service-oriented architecture.However,it does not address how to preserve the privacy of sensitive attributes and policies,which limits the promotion value of this standard.In light of this issue,in this paper we propose that to extend XACML access control model with hidden credential technology,which preserves the privacy of sensitive attributes and policies on both interactive sides,so that the automated trust negotiation based on XACML access control model is achieved.Meanwhile,the organisation method and approach for confidential policy in XACML standard is also depicted in this paper.At the end of the paper the safety of the extended access control model is analysed,and it is proven that the model can run well against various types of general distributed attacks.

关 键 词:隐藏证书 信任协商 访问控制 可扩展访问控制标记语言 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象