计算机工程与应用 ›› 2008, Vol. 44 ›› Issue (19): 12-15.

• 博士论坛 • 上一篇    下一篇

一种基于用户行为信任的动态角色访问控制

田立勤1,3,冀铁果1,林 闯2,杨 扬1   

  1. 1.北京科技大学 信息工程学院,北京 100083
    2.清华大学 计算机科学与技术系,北京 100084
    3.华北科技学院 计算机系,北京 101601
  • 收稿日期:2008-01-31 修回日期:2008-03-28 出版日期:2008-07-01 发布日期:2008-07-01
  • 通讯作者: 田立勤

Kind of user behaviour trust and role based dynamic access control model

TIAN Li-qin1,3,JI Tie-guo1,LIN Chuang2,YANG Yang1   

  1. 1.Information Engineering School,University of Science and Technology Beijing,Beijing 100083,China
    2.Department of Computer Science and Technology,Tsinghua University,Beijing 100084,China
    3.Department of Computer,North China Institute of Science and Technology,Beijing 101601,China
  • Received:2008-01-31 Revised:2008-03-28 Online:2008-07-01 Published:2008-07-01
  • Contact: TIAN Li-qin

摘要: 在基于角色的访问控制(RBAC)模型基础上,引入了属性的概念,增加了用户行为信任级别集合,建立了一种基于用户行为信任评估的动态角色访问控制(UT-DRBAC)模型。对新的模型进行了详细的形式化描述并讨论了模型的授权流程,最后从动态性、信任机制、角色数量和性能方面对模型的优越性进行了分析。新的访问控制模型通过角色属性的动态指派实现了模型授权的动态性,通过把用户信任级别作为一个必需的角色属性实现了基于身份信任和行为信任相结合的访问控制,改变了现有访问控制模型单一基于身份信任的静态授权机制;通过设置角色属性减少角色数量,从而缓解了因角色过多而带来的角色管理问题,同时提高了性能。

Abstract: The paper establishes a user behaviour trust and Role-Based Access Control(RBAC) model,which introduces the attribute concept and adds the user behaviour trust degree set on the basis of RBAC model.The detailed description and the authorization flow are given in the article.At last the model is analyzed from the dynamic performance and trust mechanism and role numbers and work performance.The new access control achieves the dynamic authorization by the dynamic assignment of role attributes and achieves the connection identity trust with behavior trust by setting the trust degree as an obligatory attribute,which changes the static authorization only based the identity of existing access control models.The model can reduce the role number by setting the attributes for the role,which can lighten the role management burden caused by the large number roles and improve the performance at the same time.