• 论文 •    

网格虚拟组织内访问控制策略的自动组合方法

王荣斌,陈蜀宇,王卫平,喻玲   

  1. 1.重庆大学 计算机学院,重庆400044;2.重庆高速公路发展有限公司,重庆400042;3.重庆大学 软件工程学院,重庆400044
  • 出版日期:2009-05-15 发布日期:2009-05-25

Automatic composition scheme for access control policies in grid virtual organization

WANG Rong-bin, CHEN Shu-yu, WANG Wei-ping, YU Ling   

  1. 1.College of Computer Science,Chongqing University,Chongqing 400044, China;2.Chongqing Expressway Development Ltd.,Co.,Chongqing 400042, China;3.College of Software Engineering,Chongqing University Chongqing 400044, China
  • Online:2009-05-15 Published:2009-05-25

摘要: 为实现网格中安全策略的动态生成,提出了基于访问控制策略集自动组合的方法。虚拟组织根据网格服务组合约束,建立相关自治域访问控制策略集的组合关系。利用代数集合理论实现策略集的组合运算,通过自动组合引擎和组合触发规则,实现访问控制策略集的自动组合,生成虚拟组织内的访问控制策略集。由于自动组合后的策略集存在冗余子集和操作权限冲突,提出了操作权限自动合并方法和冲突解决办法,并提出了自动组合算法。经分析证明,该方法在网格环境下具有较强的灵活性和动态适应性。

关键词: 网格, 虚拟组织, 访问控制, 策略集, 自动组合, 权限合并

Abstract: To realize dynamic generation of the access control policies and improve the dynamic adaptability of authorization verification for requester in grid,the automatic composition scheme for access control policy set in grid was put forward. According to the services composition constraints, the composition relationships of policy set for autonomous domains of Virtual Organization (VO) was constructed. The theory of algebra set was used to implement composition and computing for the policy set. And the automatic composition for policy set was realized by means of automatic composition engine and automatic trigger rules,and the access control polices set in VO was therefore generated. As there might be conflicts and redundancy policy subset in composed polices set,a method to resolve conflicts and automatic permission combination was proposed. The automatic composition algorithm was also presented. By analysis and implementation of the scheme, it was demonstrated that the scheme was with higher flexibility and dynamic adaptability.

Key words: grid, access control, virtual organization, policy set, automatic composition, permission combination

中图分类号: