首页 | 本学科首页   官方微博 | 高级检索  
     

跨域访问控制策略合成的可视化框架
引用本文:潘理,柳宁,訾小超. 跨域访问控制策略合成的可视化框架[J]. 中国通信, 2013, 10(3): 67-75. DOI: 10.1109/CC.2013.6488831
作者姓名:潘理  柳宁  訾小超
摘    要:

收稿时间:2013-03-27;

Visualization Framework for Inter-Domain Access Control Policy Integration
PAN Li,LIU Ning,ZI Xiaochao. Visualization Framework for Inter-Domain Access Control Policy Integration[J]. China Communications, 2013, 10(3): 67-75. DOI: 10.1109/CC.2013.6488831
Authors:PAN Li  LIU Ning  ZI Xiaochao
Affiliation:School of Electronic Information and Electric Engineering, National Engineering Laboratory of Information Content Analysis Technology, Shanghai Jiao Tong University, Shanghai 200240, China
Abstract:The rapid increase in resource sharing across domains in the cloud computing environment makes the task of managing inter-domain access control policy integration difficult for the security administrators. Although a number of policy integration and security analysis mechanisms have been developed, few focus on enabling the average ad-ministrator by providing an intuitive cognitive sense about the integrated policies, which considerably undermines the usability factor. In this paper we propose a visualization framework for inter-domain access control policy integration, which integrates Role Based Access Control (RBAC) policies on the basis of role-mapping and then visualizes the integrated result. The role mapping algorithm in the framework considers the hybrid role hierarchy. It can not only satisfy the security constraints of non-cyclic inheritance and separation of duty but also make visualization easier. The framework uses role-permission trees and semantic substrates to visualize the integrated policies. Through the interactive policy query visualization, the average administrator can gain an intuitive understanding of the policy integration result.
Keywords:policy visualization  policy integration  role based access control  role mapping
点击此处可从《中国通信》浏览原始摘要信息
点击此处可从《中国通信》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号