首页 | 官方网站   微博 | 高级检索  
     

面向Web服务的基于属性的访问控制研究
引用本文:沈海波 洪帆. 面向Web服务的基于属性的访问控制研究[J]. 计算机科学, 2006, 33(4): 92-96
作者姓名:沈海波 洪帆
作者单位:华中科技大学计算机学院,武汉,430074;华中科技大学计算机学院,武汉,430074
基金项目:湖北省自然科学基金;湖北省教育厅科研项目
摘    要:Web服务是一种新的面向服务的计算模式,由于其异构性、多域性和高度动态性,它提出了独特的安全挑战。一个关键的安全挑战就是要设计有效的访问控制机制。但目前存在的访问控制机制大多是基于身份的,存在严重的管理规模和控制粒度问题。本文提出利用基于属性的访问控制(Attribute-Based Access Control,ABAC)机制来处理Web服务的访问控制问题。ABAC采用相关实体的属性进行授权决策,能解决管理规模问题,并提供细粒度的控制。另外,文中对ABAC进行了建模,讨论了其应用,最后还给出了一种实施框架。

关 键 词:Web服务  基于属性的访问控制  RBAC  SAML  XACML

Study on Attribute-Based Access Control for Web Services
SHEN Hai-Bo,HONG Fan (School of Computer,Huazhong University of Science and Technology,Wuhan. Study on Attribute-Based Access Control for Web Services[J]. Computer Science, 2006, 33(4): 92-96
Authors:SHEN Hai-Bo  HONG Fan (School of Computer  Huazhong University of Science  Technology  Wuhan
Affiliation:School of Computer, Huazhong University of Science and Technology, Wuhan 430074
Abstract:Web service is a new service-oriented computing paradigm which poses the unique Security challenges due to its inherent heterogeneity,multidomain characteristic and highly dynamic nature.A key challenge in Web services se- curity is the design of effective access control schemes.However,the most of current access control systems is based authorization decisions on subject identity,occrues serious administrative sealability and control granularity problems. In this paper,an attribute-based access control (ABAC) model is presented to address these issues.ABAC grants ac- cesses to services based on the attributes possessed by related entities,and can provide administratively scalable alterna- tive to identity-based authorization methods and provide fine-grained access control for Web services.Moreover,we de- velop a pattern for ABAC,discuss its application issues,and also describe the implementation architecture for the sys- tem in the end.
Keywords:RBAC  SAML  XACML
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号