• 论文 •    

分布式服务共享的访问控制技术

梁策,肖田元,张林鍹   

  1. 清华大学 自动化系国家CIMS工程研究中心, 北京100084
  • 出版日期:2007-03-15 发布日期:2007-03-25

Access control model in distributed service sharing

LIANG Ce, XIAO Tianyuan, ZHANG Linxuan   

  1. National CIMS Eng. Research Cent., Dep. of Automation, Tsinghua Univ., Beijing100084, China
  • Online:2007-03-15 Published:2007-03-25

摘要: 为实现服务共享,需要在异构访问控制模型之间建立分布式的访问控制机制。以ARBAC97访问控制模型为基础,引入代理系统,在不同的访问控制架构之间,建立分布式角色定义框架,给出了构建与共享服务相关的代理角色的方法,提供代理管理角色完整性的验证工具,从而避免了权限泄漏,细化了授权粒度,解决了分布式角色系统工程中的管理问题。最后,讨论了代理系统的实现机制,并在网络化制造服务平台集成中得到应用。

关键词: 访问控制, 服务共享, 代理系统, 代理角色验证

Abstract: To realize service sharing, an access control mechanism was needed for heterogeneous access control models. Based on Administrator Role Based Access Control Model (ARBAC97), Agent system was introduced, and distributed role definition framework for different access control architectures was constructed. Approaches to construct the delegation roles associated with specified shared services and verification tool for integrity of delegation administrative role were presented. This method avoided the privilege leakage, improved authorization granularity and facilitated the management of shared services. The architecture and implementation mechanism of delegation access control model were discussed and applied in networked manufacturing service platforms integration.

Key words: access control, service sharing, Agent system, delegation role verification

中图分类号: