期刊导航

论文摘要

Web服务语义安全供求策略研究

Research on Semantic Security Supply-and-Demand Policy for Web Service

作者:贺正求(解放军理工大学指挥自动化学院)

Author:He Zheng-Qiu()

收稿日期:2010-05-12          年卷(期)页码:2011,43(1):116-122

期刊名称:工程科学与技术

Journal Name:Advanced Engineering Sciences

关键字:Web服务;安全策略;语义;包含推理

Key words:web service; security policy; semantic; subsumption

基金项目:国家重点基础研究发展计划

中文摘要

目前,Web服务安全供求策略的表示与匹配是句法层次的,通过比较策略在结构和词法上的相似性来确定其兼容性,容易导致错误的匹配结果。为此,论文提出了基于语义思想来表示和匹配Web服务安全供求策略的方法。通过构造一个一般性的安全本体,提出了Web服务语义安全供求策略的定义方法和匹配算法,将策略的匹配问题转化成语义概念的包含推理问题。理论分析和实验结果表明,本文提出的方法能使策略内容包含必要的语义信息,可有效提高匹配结果的准确性,克服句法级方法存在的不足,同时也能在一定程度上简化策略的定义与管理,从而为Web服务环境下的安全供求策略表示与匹配问题提供了一个更为有效的解决方案。

英文摘要

Presently, most schemes use syntactic approaches to represent and match the security policy for web service, where pairs of policies are compared for structural and syntactic similarity to determine compatibility, which is prone to result in false negative because of lacking semantics. In this paper, we proposed a novel approach to express and match the security supply-and-demand policy of web service based on semantics. Through constructing a general security ontology, we presented the definition method and matching algorithm of semantic security supply-and-demand policy for web service, and translated the matching problem of security policy into the semantic based subsumption reasoning problem. Both the theory analysis and experiment evaluation show that, the proposed approach can present the necessary semantic information in the representation of policy and effectively improve the accuracy of matching result, thus overcome the deficiency of the syntactic approaches, and can also simplify the definition and administration of the policy at the same time, which thereby provides a more effective solution for the expression and matching problem of security policy in web service environment.

关闭

Copyright © 2020四川大学期刊社 版权所有.

地址:成都市一环路南一段24号

邮编:610065