• 论文 •    

制造网格中访问控制的研究

蔡红霞,俞涛,方明伦   

  1. 上海大学 机电工程与自动化学院CIMS和机器人中心,上海200072
  • 出版日期:2007-04-15 发布日期:2007-04-25

Access control of manufacturing grid

CAI Hong-xia, YU Tao, FANG Ming-lun   

  1. CIMS & Robot Cent., Sch. of Mechatronics Eng. & Automation, Shanghai Univ., Shanghai200072, China
  • Online:2007-04-15 Published:2007-04-25

摘要: 针对制造网格开放的系统框架、动态的组织结构和复杂的业务流程等特性,提出了一种基于网格社区授权服务框架的动态、分粒度访问控制解决方案。在该方案中,制造网格的访问控制模型扩展了基于角色的访问控制模型。全局细粒度的访问控制策略确定用户对应角色的全局权限;根据项目状态,动态调整角色的可执行权限,本地粗粒度的访问控制策略确定服务的共享权限;服务节点做出授权决策。应用实例证明,制造网格访问控制模型支持动态授权及制造网格服务节点自主控制,可以增强制造网格的安全性。

关键词: 制造网格, 社区授权服务, 基于角色的访问控制, 安全

Abstract: Based on the Community Authorization Service (CAS) architecture, an access control solution was proposed to satisfy the inherent natures of the Manufacturing Grid (MG), such as open architecture, dynamic organization and complicated business processes. In this solution, the Manufacturing Grid Access Control (MGAC) model extended the Role-based Access Control (RBAC) model. In the MGAC model, global fine-grained policies were used to authorize users' global privileges. Enabled privileges could be adjusted according to the current project state. The local coarse-grained access control policies were used to define the privileges of the shared services. The authorization decision was made by a local service node based on the local access control polices and the global privileges of users. The implementation in Shanghai High Institutions Grid proved that the access control model could support the dynamic authorization and local management and improve the security of MG.

Key words: manufacturing grid, community authorization service, role-based access control, security

中图分类号: