摘要
网格具有异构、动态、多域的特点,这给网格的安全研究带来了新的挑战。网格安全基础设施(GSI)解决了网格环境下的安全认证和安全通信,但没有对访问控制问题足够重视。传统的访问控制方法仅仅从访问资源的角度来解决安全问题。主体操作方式的多样性和用户计算环境的异构性导致了网格环境的动态性和不确定性。当这种动态性对访问主体造成影响时就需要改进访问控制方法,要求访问控制系统能够动态适应网格环境的安全状态变化。针对该问题本文提出了在访问控制前加入安全评估模型(SEMFG),由该模型对访问环境和访问主体进行综合评估,监控网格环境和访问主体的行为,并用评估结果动态指导访问控制。
The emerging Grid infrastructure research presents many challenges due to its inherent heterogeneity,dynamics and multidomain characteristics. GSI,the grid security infrastructure mainly oriented to security authentication and communications,pays insufficient attention to the access control. The traditional access control methods are mainly concerned about the security problems of the provider of resources and miss the protection of the access requesters. The diversity of the operation and user heterogeneous computing environments lead to the dynamic Grid environment and uncertainty.The access control method should be improved when dynamic and uncertain changes of the grid environment affect the access requester. It should be asked to dynamically adapt to the security status changes of the grid environment. In this paper we present a security evaluation model for grid (SEMFG) in order to evaluate the security of the access environment and the requester .Evaluation results can guide the access control.
出处
《计算机工程与科学》
CSCD
北大核心
2010年第10期16-19,共4页
Computer Engineering & Science
关键词
安全评估
动态
访问控制
网格
security evaluation;dynamic;access control;grid