首页 | 本学科首页   官方微博 | 高级检索  
     

电力信息系统中基于属性的访问控制模型的设计
引用本文:王保义,王蓝婧.电力信息系统中基于属性的访问控制模型的设计[J].电力系统自动化,2007,31(7):81-84.
作者姓名:王保义  王蓝婧
作者单位:华北电力大学计算机学院,河北省保定市,071003
基金项目:基于高速广域网和多Agent的电网自适应协调保护系统(基金号:50477038)
摘    要:电力信息系统构成一个复杂的多域环境,它为电力行业进行信息交换和协作带来便捷的同时,也带来了极大的安全隐患。由于多域环境下存在多种应用系统,且用户数目众多、来源广泛,给传统的基于角色访问控制(RBAC)模型带来了用户 — 角色赋值工作量大、多域间映射困难等问题。文中针对多域环境设计了一种基于属性的访问控制模型,属性是在角色的基础上扩展得来的,并提出利用元属性和元策略分别对域内的属性和策略进行描述,充分满足电力信息系统所处的异构环境和所有者对资源进行自主管理的需求,保证了域内、域外用户对系统资源进行访问的安全。

关 键 词:电力信息系统  访问控制    RBAC  属性  多域  元策略  元属性
收稿时间:9/5/2006 8:09:34 PM
修稿时间:3/10/2007 7:44:23 PM

Design of Attribute-based Access Control Model for Power Information Systems
WANG Baoyi,WANG Lanjing.Design of Attribute-based Access Control Model for Power Information Systems[J].Automation of Electric Power Systems,2007,31(7):81-84.
Authors:WANG Baoyi  WANG Lanjing
Affiliation:North China Electric Power University, Baoding 071003, China
Abstract:The power information system constitutes a complex multi-domain environment. While providing convenient information exchange and coordination to the power industry, it also brings some security problems, especially the access control issues. As there are quite a lot of application systems in the multi-domain environment, and the accessing users may be from different domains, the traditional RBAC model is confronted with problems, such as the tedious user-role assignment and mapping difficulty across different domains. So an attribute-based access model for multi-domain control is designed. Extended from roles, attributes can overcome these shortcomings of RBAC and make access control more flexible, dynamic and finegrained. Meta-attribute and meta-policy are presented to describe the attributes and policies in local domains. It can adapt well to the distributed environment, satisfy the dynamic and heterogeneity character and the self-management to their resources.
Keywords:power information systems  access control  RBAC  attribute  multi-domain  meta-policy  meta-attribute
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《电力系统自动化》浏览原始摘要信息
点击此处可从《电力系统自动化》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号