论文部分内容阅读
基于属性的访问控制模型具有授权灵活、控制粒度细的特点,针对服务网格的特点,提出基于属性自动合并的访问控制模型.沿服务有向图的服务组合路径,自动进行属性集合的合并计算,从而实现访问控制约束属性在网格虚拟组织内自动生成.授权不需要人工干预和具有用户的先验知识,可使用户在执行需要跨越多个自治域组合服务所需的约束属性集合一次性指派给用户,用户访问时一次性完成多个自治域的访问授权.具有极大的灵活性、动态性和可扩展性.
Attribute-based access control model has the characteristics of flexible authorization and fine granularity of control, and based on the characteristics of service grid, an access control model based on attribute automatic combination is proposed.According to the service composition path of service directed graph, the attribute combination is calculated automatically So that the access control constraint attributes can be automatically generated in the grid virtual organization.Authorization does not require human intervention and has the prior knowledge of the user so that the user can perform the one-time set of constraint attributes needed to implement the service that needs to be combined across multiple AS domains Assigned to the user, the user access to multiple autonomous domain access authorization at once. Has great flexibility, dynamic and scalability.