论文部分内容阅读
首先提出了基于属性的访问控制策略,该方法利用用户和角色属性表达式来描述访问控制策略.然后,提出了扩展的XACML(扩展访问控制标记语言)策略描述语言A-XACML.A-XACML可以简单、灵活地表达各种应用环境中的访问控制策略,尤其是基于属性的访问控制策略.该语言及其框架通过数据类型、函数和逻辑组合来定义简单或复杂的访问控制策略.最后,给出了利用属性表达式和A-XACML来实现用户-角色指派的系统架构和应用实例.该实例表明属性表达式和A-XACML能够灵活简单地描述和实施复杂的访问控制策略.
Firstly, a property-based access control strategy is proposed, which uses the user and role attribute expressions to describe the access control strategy.Then, an extended XACML (Extended Access Control Markup Language) policy description language A-XACML is proposed.A-XACML Simple and flexible to express the access control strategies in various application environments, especially the attribute-based access control strategies.These languages and their frameworks define simple or complex access control strategies through data types, functions and logical combinations.Finally, The system architecture and application examples of user-role assignment using attribute expressions and A-XACML are presented.The example shows that attribute expressions and A-XACML can flexibly and simply describe and implement complex access control policies.