
• 信息安全 • 上一篇    下一篇



  1. (南京航空航天大学计算机科学与技术学院,江苏南京210016)
  • 收稿日期:2018-09-07 出版日期:2019-07-05 发布日期:2019-07-08
  • 作者简介:张芃(1993-),女,山东青岛人,硕士研究生,研究方向:系统集成,E-mail: gegzhang@yeah.net; 周良(1966-),男,湖南长沙人,副教授,博士,研究方向:系统集成,E-mail: betazllj@nuaa.edu.cn。

Trust-based Dynamic Multi-level Access Control Model

  1. (College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China)
  • Received:2018-09-07 Online:2019-07-05 Published:2019-07-08

摘要: 针对传统基于角色的访问控制(Role-Based Access Control, RBAC)系统中的访问资源共享伸缩性有限、安全性不足及权限需预先设定分配等问题,为了提高权限控制的兼容性,细化访问控制粒度,本文提出一种基于信任的动态多级访问控制模型(Trust-Based Dynamic Multi-level Access Control Model, TBDMACM),通过用户的静态角色及动态信任度获得相应的权限授权,保证数据机密性和访问过程安全可控。实验结果表明,这种访问控制方式能够有效地防止恶意访问,较好地解决系统权限伸缩性问题。

关键词: 访问控制, 可信度, 多级安全

Abstract:  Aiming at the problems of limited scalability, inadequate security and permission allocation in traditional role-based access control (RBAC) models, in order to improve the compatibility of access control and refine the granularity of access control, this paper proposes a trust-based dynamic multi-level access control model (TBDMACM). TBDMACM guarantees data confidentiality and security of access process by obtaining corresponding authorization through the static roles and dynamic trust of users. The experimental results show that the proposed method can effectively prevent malicious access and better solve the problem of system privilege scalability.

Key words: access control, credibility, multi-level security
