摘要
论文在分析现有访问控制模型和技术的基础上,结合多元判决与动态访问控制的思想,提出了一种基于多元判决的动态通用访问控制架构,并重点阐述了多元判决与动态授权管理的设计思路,对架构中各模块、数据库进行了介绍。本体系架构克服了现有访问控制技术中判决依据单一、授权方式无法满足部分应用业务安全需求的不足,为访问控制实现提供了新的思路。
Based on analyzing current models and technologies in access control domain, it is found that most of the access control systems in use implement authorization only by user identity. When the network environment turns into insecurity, the system is unable to change its policy to handle such situation by itself. So in this paper, a new architecture of access control is proposed, which determines customers' privileges by multi-decision and dynamic management. A detailed design of multi-decision and dynamic management pattern is given and then the description of key modules and database is followed. This architecture provides a solution to the problem mentioned above and new thoughts in access control.
出处
《信息安全与通信保密》
2009年第4期44-46,49,共4页
Information Security and Communications Privacy
关键词
访问控制
多元
动态
LDAP
access control
multi-decision
dynamic control
LDAP