Computer Science ›› 2020, Vol. 47 ›› Issue (7): 56-65.doi: 10.11896/jsjkx.190700157

Research Progress on Risk Access Control

WANG Jing-yu, LIU Si-rui   

  1. School of Information Engineering,Inner Mongolia University of Science and Technology,Baotou,Inner Mongolia 014010,China
  • Received:2019-07-22 Online:2020-07-15 Published:2020-07-16
  • About author:WANG Jing-yu,born in 1976,Ph.D,professor,is a member of China Computer Federation.His main research interests include cloud computing and information security.
    LIU Si-rui,born in 1993,postgraduate.Her main research interests include information security and big data access control.
  • Supported by:
    This work was supported by the National Natural Science Foundation of China(61662056) and Natural Science Foundation of Inner Mongolia Autonomous Region,China(2016MS0609,2016MS0608)

Abstract: Big data access control is one of the important technologies to ensure the security and information sharing of big data.However,because the traditional access control strategy can not meet the real-time and dynamic access information in the dynamic environment,the risk assessment method is introduced in the access control to coordinate access control policies,improve the application of access control in dynamic environments.In view of this,this paper systematically reviews and summarizes the main work of risk access control research at home and abroad,and analyzes the latest research results in recent years.Firstly,the risk access control extended to the traditional access control model and its XACML framework-based access control model is analyzed and summarized,and the application in different environments is summarized.Secondly,the techniques and methods of risk access control are summarized and analyzed,the risk is self-contained,and Risk-Adaptive Access Control (RAdAC) is analyzed and researched.Finally,the future research on risk access control in big data environment is prospected,and some problems with research value are proposed.This paper argues that risk-based access control is still an important research content of access control in future big data access control research technology.

Key words: Access control, Risk quantification, Risk factor, Risk threshold, Risk-adaptation

  TP391
