期刊文献+

基于教育云平台数据分类分级体系的访问控制模型 被引量:3

An Access Control Model Based on Data Classification and Grading System for Education Cloud Platform
下载PDF
导出
摘要 教育云平台是教育数字化建设的重要基础设施之一,其核心是通过统一来自不同部门和机构的业务数据消除信息孤岛,避免信息系统的重复建设.然而,教育云平台在实现数据共享的同时,也因其自身的开放性和动态性严重影响了数据资源安全.针对教育云平台中的数据管控,提出一种基于数据分类分级体系的访问控制模型.该模型综合考虑了数据分类、安全等级、生命周期和敏感性等安全特性,为数据打上多维度安全标签;将安全标签与基于角色的访问控制策略融合,通过粗粒度过滤和细粒度控制的2级授权集中管理数据权限.经原型系统验证,该模型能有效实现云平台中数据的受限共享,防止用户越权操作. The education cloud platform is one of the key infrastructures for education digitization construction.It unifies business data from different departments and organizations to eliminate information silos and reduce the redundant construction of information systems.However,although the education cloud platform realizes data sharing,it also seriously influences the security of data resources because of its open and dynamic characteristics.Considering the data management and control of the education cloud platform,this paper proposes an access control model based on data classification and grading system.The model comprehensively considers the security factors such as data class,security grade,life cycle and sensitive level,and tags the data from multidimension views.The secure tag is integrated with the role-based access control policy to construct a two-stage authorization model of coarse-grained filtering and fine-grained control for managing data.The prototype system proves that the proposed model can restrict data sharing and prevent users from over-privileged manipulation.
作者 范新民 林晖 陈圣楠 陈恩生 Fan Xinmin;Lin Hui;Chen Shengnan;Chen Ensheng(Network and Data Center,Fujian Normal University,Fuzhou 350117;College of Computer and Cyber Security,Fujian Normal University,Fuzhou 350117;University Engineering Research Center of Cyber Security and Education Informatization in Fujian Province,Fuzhou 350117)
出处 《信息安全研究》 2022年第4期400-407,共8页 Journal of Information Security Research
基金 国家自然科学基金项目(U1905211) 福建省科技项目(2021L3032) 福建省自然科学基金项目(2020J01169) 福建省中青年教师教育科研项目(JAT200071)。
关键词 云平台 数据安全 访问控制模型 数据分类分级 安全标签 RBAC cloud platform data security access control model data classification and grading secure tag RBAC
  • 相关文献

参考文献9

二级参考文献66

  • 1洪帆,饶双宜,段素娟.基于属性的权限—角色分配模型[J].计算机应用,2004,24(B12):153-155. 被引量:6
  • 2李鸿.一种基于粗糙熵的知识约简算法[J].计算机工程与应用,2005,41(14):78-80. 被引量:11
  • 3姚寒冰,胡和平,卢正鼎,李瑞轩.基于角色和上下文的动态网格访问控制研究[J].计算机科学,2006,33(1):41-44. 被引量:9
  • 4TIAN L, LIN C, NI Y. Evaluation of user behavior trust in cloud computing [ C]// ICCASM 2010: Proceedings of the 2010 Interna- tional Conference on Computer Application and System Modeling. Piscataway: IEEE, 2010, 7:567-572. 被引量:1
  • 5ZHU T, LIU W, SONG J. An efficient role based access control system for cloud computing [ C]// CIT 2011: Proceedings of the 2011 IEEE 1 lth International Conference on Computer and Informa- tion Technology. Piscataway: IEEE, 2011:97-102. 被引量:1
  • 6SANDHU R S, COYNE E J, FEINSTEIN H L, et al. Role-based ac- cess control models [J]. IEEE Computer, 1996, 29(2): 38 -47. 被引量:1
  • 7LI W, WAN H, REN X, et al. A refined RBAC model for cloud computing [ C]// ICIS 2012: Proceedings of the 2012 IEEE/ACIS 11 th International Conference on Computer and Information Science, Piscataway: IEEE, 2012:43-48. 被引量:1
  • 8WANG W, HAN J, SONG M, et al. The design of a trust and role based access control model in cloud computing [ C]//ICPCA 2011: Proceedings of the 2011 6th International Conference on Pervasive Computing and Applications. Piscataway: IEEE, 2011 : 330 - 334. 被引量:1
  • 9WU C, LI Z, CUI X. An access control method of cloud computing resources based on quantified-role [ C]//ICCT 2012: Proceedings of the 2012 14th Intenaational Conference on Communication Tech- nology. Piscataway: IEEE, 2012:919-923. 被引量:1
  • 10Hirzalla M. Realizing business agility requirements through SOA and cloud computing. Proc. of the 2010 18th IEEE International Requirements Engineering Conference. 2010. 被引量:1

共引文献77

同被引文献30

引证文献3

二级引证文献3

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部