摘要
在XACML(extensible access control markup language)和其管理性策略草案的基础上,针对目前XACML访问控制框架的特点,提出将XACML策略管理权限判定归结为利用委托策略对一个委托判定请求的判定,使用XML(extensible markup language)模式定义了此委托判定请求语法,描述了将策略管理请求规约为一个委托判定请求的过程,以及根据委托策略进行委托判定请求的判定过程,通过这种方法可以利用委托策略,对策略管理请求是否有效进行判断,从而实现基于扩展XACML的策略管理。
Based on XACML core specification and XACML administrative policy draft, a decision of XACML policy management permission was reduced to a decision of delegation decision request. The delegation decision request schema was defined. It was described that the process of reducing a policy administration request to a delegation decision request and the decision process of delegation decision request. This method can be used to check if a policy administration request is valid and thereby to implement access control policy management based on extended-XACML.
出处
《通信学报》
EI
CSCD
北大核心
2007年第1期103-110,共8页
Journal on Communications
基金
国家高技术研究发展计划("863"计划)基金资助项目(2004AA147070)
国家自然科学基金资助项目(60603017)~~
关键词
访问控制
策略管理
XACML
access control
policy management/administration, XACML