计算机工程与应用 ›› 2013, Vol. 49 ›› Issue (19): 83-87.

• 网络、通信、安全 • 上一篇    下一篇

面向业务流程访问控制策略及决策优化方法

商  铮1,2,张  斌1,2   

  1. 1.解放军信息工程大学 电子技术学院,郑州 450004
    2.河南省信息安全重点实验室,郑州 450004
  • 出版日期:2013-10-01 发布日期:2015-04-20

Access control policy for business process and its optimal methods in policy decision

SHANG Zheng1,2, ZHANG Bin1,2   

  1. 1.Institute of Electronic Technology, PLA Information Engineering University, Zhengzhou 450004, China
    2.Henan Province Key Laboratory of Information Security, Zhengzhou 450004, China
  • Online:2013-10-01 Published:2015-04-20

摘要: 在分析业务流程访问控制策略需求的基础上,对经典的XACML策略实施框架进行了扩展,提出一种能够根据业务流程执行状态管理策略的实施框架。通过在策略模式中引入<PolicyIssuer>元素和定义<Condition>元素的语义,使其能够描述访问策略和委托策略,并支持任务级最小特权的实现。给出了两种策略决策优化方法,针对策略集中无效策略数量过多的问题,采用逐步裁减法减少策略元素比对的次数,针对策略集中委托策略数量过多且需要验证可信性的问题,采用信任关联法减少策略匹配的次数,有效地提高了策略决策的效率。

关键词: XACML策略, 访问控制, 业务流程, 策略, 委托

Abstract: By analyzing the requirements of access control for business process, an extended enforcement framework that supports policy management based on state of business process is proposed. By introducing element < PolicyIssuer> and defining semantic of element <Condition> in policy schema, access control policy and delegation policy can both be described and least privilege at task level can be achieved. In order to reduce time cost of policy decision in case that numbers of unrelated policies and delegation policies are large, two methods which can reduce the numbers of matching policies and policy elements are proposed.

Key words: Extensible Access Control Makeup Language(XACML), access control, business process, policy, delegation