计算机应用 ›› 2012, Vol. 32 ›› Issue (12): 3426-3429.DOI: 10.3724/SP.J.1087.2012.03426

• 信息安全 • 上一篇    下一篇

带有委托功能的UCONpreA模型安全性分析及DBRM0表达

叶春晓,余一丰   

  1. 重庆大学 计算机学院,重庆 400044
  • 收稿日期:2012-06-05 修回日期:2012-07-17 发布日期:2012-12-29 出版日期:2012-12-01
  • 通讯作者: 余一丰
  • 作者简介:叶春晓(1973-),男,重庆人,教授,博士,主要研究方向:访问控制、数据库、软件工程;〓余一丰(1987-),男,河南息县人,硕士研究生,主要研究方向:信息安全、访问控制。

Safety analysis for UCONpreA model with delegation feature and expression for DBRM0

YE Chun-xiao,YU Yi-feng   

  1. School of Computer Science,Chongqing University,Chongqing 400044,China
  • Received:2012-06-05 Revised:2012-07-17 Online:2012-12-29 Published:2012-12-01
  • Contact: YU Yi-feng

摘要: 针对使用控制模型(Usage Control, UCON)中加入委托功能后安全分析愈加复杂的问题,本文首先形式化地表达了其子模型—使用前授权(UCONpreA)的委托过程,通过分析证明了一般带有委托功能的UCONpreA模型的安全性是不可确定的,然后通过构造有限状态机的方法证明了一个受约束的带有委托功能的UCONpreA模型的安全性是可确定的,最后利用该约束模型成功地表达了传统的基于角色的委托模型(RBDM0)。本研究进一步增强了UCON的表达能力,并有效保证其安全性。

关键词: 使用控制, 安全性分析, 有限状态机, 委托, 基于角色的委托模型

Abstract: In order to resolve the problem of safety analysis for Usage Control with delegation feature, this article first formalized the delegation process for its one child model, pre-authorization model; the security of a general UCONpreA model with delegation feature was undecidable through analysis, by means of constructing a finite state machine, the security of a constrained UCONpreA model with delegation feature was proved decidable; lastly, the traditional role based delegation model was simulated successfully using the constrained model. This research enhances the expression power of UCON even further, and ensures its safety effectively.

Key words: usage control, safety analysis, finite state machine, delegation, RBDM0

中图分类号: