计算机科学 ›› 2012, Vol. 39 ›› Issue (Z6): 343-349.

• • 上一篇    下一篇

基于属性和主体、操作和客体分层描述的逻辑授权语言

翟浩良,夏兰亭,李磊   

  1. (中山大学软件研究所 广州510275)
  • 出版日期:2018-11-16 发布日期:2018-11-16

Logical Authorization Language Based on Attribute and Subject-Operation-Object Stratification

  • Online:2018-11-16 Published:2018-11-16

摘要: 安全策略是访问控制的核心,安全策略的描述、验证和执行离不开授权语言。在实际应用中,安全需求具有复杂性和动态性的特.奴,而现有的授权语言不能很好地适应这一特点,并不能对多种访问控制策略提供足够的支持。提出了一种基于属性和主体、操作和客体分层描述的逻辑授权语言((SOOSAL) 。SOOSAL以一阶逻辑为基础,通过谓词对主体、客体和操作进行刻画,并以分层的方式通过规则对主体、操作和客体之间的关系进行描述。此外,SOOSAI从逻辑语义世界假设的角度对现实世界中的策略进行了分类:封闭性世界策略和开放性世界策略,并对这两种策略的安全性进行了讨论,给出安全性问题的简单解决方案。实例结果表明,SOOSAI、具有较强的策略描述能力,能更好地实现策略的动态变化,并对不同的安全需求和授权原则提供良好的支持。

关键词: 授权语言,逻辑,属性,分层

Abstract: Security policy is the key of access control, and the description, authentication and execution of policy can not be realized without authorization language. In practice, the existing authorization languages are not well adapted to the complex and dynamic nature of security requirements and can not provide enough support for access control model. This paper proposed a logical authorization language based on attribute and subject operation-object stratification(SOCKSAL). Based on first order logic,SOOSAL describes the subject,operation,and object by predication, and the relationship of these by rules. In addition, policy was classified into closed world policy and open world policy from the logic point of view of the world and a simple solution was given under security discussion of the two types of policies. Our experimental results show that SOOSAL has a strong descriptive power, and can achieve the policy of dynamic change and support different security requirements and authority principle better.

Key words: Authorization language, Logic, Attribute, Stratification

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!