计算机工程与应用 ›› 2015, Vol. 51 ›› Issue (7): 84-87.

• 网络、通信、安全 • 上一篇    下一篇

基于OSBE的属性访问控制模型

李冬辉,张  斌,费晓飞   

  1. 解放军信息工程大学,郑州 450014
  • 出版日期:2015-04-01 发布日期:2015-03-31

Attribute access control model based on OSBE

LI Donghui, ZHANG Bin, FEI Xiaofei   

  1. PLA Information Engineering University, Zhengzhou 450014, China
  • Online:2015-04-01 Published:2015-03-31

摘要: 针对基于属性的访问控制模型(Attribute-Based Access Control,ABAC)不支持对敏感属性的保护和权限变更的问题,提出基于OSBE的属性访问控制模型。通过改用属性证书的签名,使用户的敏感属性信息不再直接暴露给访问控制模块;通过增加采用属性证书签名的协商过程,保护属性库中的属性信息不再被策略决策点随意获取;通过在策略执行点中设计的检测模块和更新模块,支持访问控制过程中的权限变更。通过有限状态机证明了模型的安全性,并通过实例分析表明模型能够支持对属性的保护和授权变更。

关键词: 属性访问控制, OSBE技术, 敏感属性, 权限变更, 有限状态机

Abstract: Access control model based on attribute cannot support the protection of sensitive attribute and the implement of permission changing. Using the signature of the attribute certificate ensures that the subject’s attribute is no longer directly exposed to the authorization module. By introducing the attribute certificate signing negotiation guarantees that the attribute in the repository will no longer be ambitious accessed by Policy Decision Point(PDP); by designing the testing and update functions in the Policy Enforcement Point(PEP) implements the permission changing in the process of access. At last, the safety of the module is testified by using FSM(Finite State Machine), and example analysis indicates that the model can support the protection of sensitive attribute and the implement of permission changing.

Key words: access control attribute-based access control, changing permission, Oblivious Signature-Based Envelope(OSBE), sensitive attribute, Finite State Machine(FSM)