论文部分内容阅读
提出了一种将分级密钥授权融入角色管理的密文数据访问控制(KRBAC)模型,并基于该模型提出了一种元素级的细粒度数据保护方案.KRBAC模型通过划分独立的密钥控制域,将传统的角色扩展为由角色、角色控制域和密钥控制域构成的具有偏序集继承关系和安全约束性质的三元组;在密钥分级的基础上,通过主密钥及数据的特征信息产生元素级的加解密密钥.分析结果表明,该模型能减少角色数量,降低访问控制的复杂度,提高权限分配的合理性,并能为细粒度的数据保护提供安全基础.
This paper proposes a Kernel-Granular Data Access Control (KRBAC) model which integrates hierarchical key authorization into role management and proposes an element-level fine granularity data protection scheme based on the model.KRBAC model is divided into independent key control domains , The traditional role is expanded into a triplet with the properties of partial order set inheritance and security constraint formed by the role, role control domain and key control domain. Based on the key hierarchy, The result shows that this model can reduce the number of roles, reduce the complexity of access control, improve the rationality of rights allocation, and provide the security foundation for fine-grained data protection.