期刊导航

论文摘要

改进的安全策略评价管理决策图

Improved Decision Diagrams for Security Policy Evaluation and Management

作者:罗霄峰(四川大学);罗万伯(四川大学)

Author:Luo Xiaofeng();Luo Wanbo(Sichuan Univ.)

收稿日期:2015-09-13          年卷(期)页码:2016,48(4):123-128

期刊名称:工程科学与技术

Journal Name:Advanced Engineering Sciences

关键字:访问控制; 决策图; 安全策略; 策略管理; XACML;

Key words:access control; decision diagrams; security policy; policy management; XACML;

基金项目:保密基金项目JG2011003

中文摘要

针对Canh Ngo等为安全策略评价和管理所提出的MIDD和X-MIDD方法的不足,本文从一般ABAC模型出发,对其进行了改进。设计了新的图结构iMIDD和iX-MIDD,新图的边用上结点变量值范围(简约的区间划分)及状态组成的元组表示,可更好地标注在决策中有关键作用的重要属性,有利于决策过程中更精细化处理。iX-MIDD的决策-叶结点也做了扩展,增加了组合算法信息,便于在对访问请求进行决策时使用。给出了应用本文方法进行策略元素匹配、策略评估,以及从iMIDD生成iX-MIDD的流程。复杂度分析及仿真实验表明,本文方法的时间、空间复杂度和性能均与MIDD方法相当。新方法完全能用于策略管理的多种应用。

英文摘要

In order to overcome the shortcomings of MIDDs approach proposed by Canh Ngo et al, some improvements are proposed. New graph structures which edge is a tuple of node-variable reduced interval partition and the state value marking critical attribute were designed for the improved MIDDs and X-MIDDs, named iMIDDs and iX-MIDDs respectively. In addition, the combining-algorithm identifier is also added to iX-MIDDs decision-leaf nodes. Operations and processing of policy elements match, policy evaluation, and iMIDD to iX-MIDD transformation are introduced. Complexities analysis and simulation show both space and evaluation time complexities of proposed approach are equivalent to the MIDDs’. New approach could be applied in various policy management problems.

关闭

Copyright © 2020四川大学期刊社 版权所有.

地址:成都市一环路南一段24号

邮编:610065