论文部分内容阅读
在面向服务的架构的环境下,由于服务的动态性,常见的自主访问控制(DAC)、强制访问控制(MAC)和基于角色的访问控制(RBAC)等传统访问控制机制,已经不能完全满足面向服务的架构(SOA)环境的要求,导致访问控制策略管理非常复杂。为了简化面向服务的架构下的访问控制策略管理,通过采用将基于属性的访问控制(ABAC,Attribute-Based Access Control)方法,可以简化对于面向服务的架构下的异构属性的授权策略。研究发现,ABAC拥有更高的灵活性和更细的访问控制粒度,能够表现语义更丰富的访问控制策略,更适用于SOA环境。
In the context of service-oriented architectures, due to the dynamic nature of services, traditional access control mechanisms such as common access control (DAC), mandatory access control (MAC) and role based access control (RBAC) Service-oriented architecture (SOA) environment requirements, resulting in access control policy management is very complex. To simplify access control policy management under service-oriented architecture, the authorization strategy for heterogeneous attributes under service-oriented architecture can be simplified by adopting the attribute-based access control (ABAC) method. The study found that ABAC offers greater flexibility and finer granularity of access control, enabling more semantic access control policies to be more applicable to SOA environments.