计算机应用 ›› 2011, Vol. 31 ›› Issue (07): 1884-1886.DOI: 10.3724/SP.J.1087.2011.01884

• 信息安全 • 上一篇    下一篇

基于互斥角色约束的SSOD策略实现研究

王婷,陈性元,张斌,任志宇,王鲁   

  1. 信息工程大学 电子技术学院,郑州 450004
  • 收稿日期:2010-12-20 修回日期:2011-02-04 发布日期:2011-07-01 出版日期:2011-07-01
  • 通讯作者: 王婷
  • 作者简介:王婷(1982-),女,河南洛阳人,博士研究生,主要研究方向:资源管理、访问控制;陈性元(1963-),男,安徽无为人,教授,博士生导师,主要研究方向:信息安全;张斌(1969-),男,河南南阳人,副教授,主要研究方向:信息安全;任志宇(1974-),女,河南汤阴人,讲师,主要研究方向:信息安全;王鲁(1962-),女,山西河曲人,教授,主要研究方向:信息安全。
  • 基金资助:

    国家863计划项目;国家863计划项目

Static eparation of duty policy base on mutually exclusive role constraints

Ting WANG,Xing-yuan CHEN,Bin ZHANG,Zhi-yu REN,Lu WANG   

  1. Institute of Electronic Technology, Information Engineering University, Zhengzhou Henan 450004, China
  • Received:2010-12-20 Revised:2011-02-04 Online:2011-07-01 Published:2011-07-01
  • Contact: Ting WANG

摘要: 静态职责分离(SSOD)是保证计算机安全的重要策略。在基于角色的权限控制(RBAC)中直接基于互斥角色约束(2-2 SMER)实现最简单的SSOD策略(2-n SSOD)是困难的。通过对互斥角色的权限分配进行约束,研究并证明了基于2-2 SMER实现2-n SSOD策略的充分条件,此充分条件和现有研究相比具有更弱的约束力,支持更灵活的权限分配。进一步给出了实现2-n SSOD策略的授权管理操作规则,以确保权限的动态管理始终满足此充分条件,维持系统对2-n SSOD策略的满足状态。最后,通过应用实例说明了实现2-n SSOD策略方法的有效性和可行性

关键词: 静态职责分离, 互斥角色约束, 授权管理, 访问控制

Abstract: Static Separation Of Duty (SSOD) is an important principle of information system security. In Role-Based Access Control (RBAC), it is difficult to enforce 2-n SSOD policy directly based on 2-2 Static Mutually Exclusive Role (SMER) constraints. In this paper, the necessary and sufficient conditions of realizing 2-n SSOD policy based on 2-2 SMER constraints were proposed and proved. The sufficient condition proposed was less restrictive than the existing research and allowed more flexible privilege assignment. By the operation rules of authorization management, the sufficient condition was kept and the satisfaction of 2-n SSOD policy during the dynamic change of application environment could be maintained. The application example shows that the method is correct and effective.

Key words: static separation of duty, mutual exclusive roles, authorization management, access control