摘要
基于属性的访问控制模型具有授权灵活、控制粒度细的特点,针对服务网格的特点,提出基于属性自动合并的访问控制模型.沿服务有向图的服务组合路径,自动进行属性集合的合并计算,从而实现访问控制约束属性在网格虚拟组织内自动生成.授权不需要人工干预和具有用户的先验知识,可使用户在执行需要跨越多个自治域组合服务所需的约束属性集合一次性指派给用户,用户访问时一次性完成多个自治域的访问授权.具有极大的灵活性、动态性和可扩展性.
The attribute-based model has the flexibility and fine grain for authorization,according to services grid,put forward the access control model based on attribute combine automatically for services grid.It implements automatic combination computing the attribute set along with the service composition path of service orient graph.So the access control constraint attributes are produced automatically in grid virtual organization,without manual operation and prior knowledge about the users,which make it possible that assign the constraint attributes to users and authorize users to access services for one time when the user's access span multi-domain.The model is much more flexible and dynamic and extensible than other models.
出处
《小型微型计算机系统》
CSCD
北大核心
2010年第8期1619-1624,共6页
Journal of Chinese Computer Systems
基金
重庆市自然科学基金项目(2008BB2307)资助
关键词
网格
服务
属性
自动合并
访问控制
grid
services
attribute
automatic combine
access control