计算机应用 ›› 2010, Vol. 30 ›› Issue (4): 1045-1047.

• 信息安全 • 上一篇    下一篇

基于扩展角色访问控制的普适计算访问控制模型

孙凌1,辛艳2,罗长远2   

  1. 1. 河南省商业高等专科学校
    2. 解放军信息工程大学电子技术学院
  • 收稿日期:2009-10-09 修回日期:2009-11-30 发布日期:2010-04-15 出版日期:2010-04-01
  • 通讯作者: 罗长远

Pervasive computing access control model based on extended RBAC

1, 1,   

  • Received:2009-10-09 Revised:2009-11-30 Online:2010-04-15 Published:2010-04-01

摘要: 针对普适计算访问控制对客体部分动态管理的需要,分析了现有扩展基于角色的访问控制(RBAC)的不足,提出一种新的扩展RBAC模型。模型引入客体与客体的关联,使得权限既可以通过角色也可以通过客体获得,并采用描述逻辑对模型访问控制过程进行了形式化描述。该模型能够实现细粒度的动态授权,解决了因决策的固有性导致角色数量过多、授权不灵活的问题。

关键词: 普适计算, 访问控制, 基于角色的访问控制, 动态描述逻辑

Abstract: Concerning the needs of dynamic management for object in pervasive computing access control and the shortages of the existing Role Based Access Control (RBAC), the paper presented an extended RBAC model. In the model an associated object was presented, so the permissions can be obtained through roles and objects. The access control processes were described with the description logic. The model considers the authorization from the point of view of object, and resolves the problems that the roles are too many and the authorization is not flexible caused by the inherence of decision.

Key words: pervasive computing, access control, Role Based Access Control (RBAC), dynamic description logic