论文部分内容阅读
为解决网络中多安全域间的访问控制难题,提出一种基于角色和信任度的访问控制模型.将角色和信任度相关联,根据用户角色等级定义角色评价权重,利用角色评价权重和角色行为计算其信任度.在引入直接信任度、推荐信任度和反馈信任度的基础上,通过调节各自的评价权重参与综合信任度评价,实现了细粒度的访问控制.在局域网环境下利用web应用系统构建具有多安全域的访问控制模型,并进行了仿真实验,实验结果证明该模型具有较高的安全性、可扩展性和灵活性.
To solve the problem of access control among multiple secure domains in the network, a role-based access control model based on trust is proposed, in which the role and trust are correlated, the role evaluation weight is defined according to the user role hierarchy, the role evaluation weight and role behavior To calculate the trust degree.With the introduction of the direct trust degree, the recommended trust degree and the feedback trust degree, the fine grained access control is achieved by adjusting their respective evaluation weights to participate in the comprehensive trust evaluation.With the web application system An access control model with multiple secure domains is constructed and simulated. The experimental results show that the model has high security, scalability and flexibility.