西安电子科技大学学报

• 研究论文 • 上一篇    下一篇

一种云平台动态风险访问控制模型

杨宏宇;宁宇光   

  1. (中国民航大学 计算机科学与技术学院,天津 300300)
  • 收稿日期:2017-10-29 出版日期:2018-10-20 发布日期:2018-09-25
  • 作者简介:杨宏宇(1969-),男,教授,博士,E-mail:yhyxlx@hotmail.com
  • 基金资助:

    国家自然科学基金资助项目(60776807,61179045);国家科技重大专项资助项目(2012ZX03002002);中国民航科技基金资助项目(MHRD201009,MHRD201205)

Cloud platform dynamic risk access control model

YANG Hongyu;NING Yuguang   

  1. (School of Computer Science and Technology, Civil Aviation Univ. of China, Tianjin 300300, China)
  • Received:2017-10-29 Online:2018-10-20 Published:2018-09-25

摘要:

针对风险访问控制模型无法动态匹配规则和风险值对访问请求灵敏度低的问题,提出一种云平台动态风险访问控制模型.首先通过事件推演机制改进基于属性的访问控制策略,构造动态规则匹配模块;然后设计动态分配风险评估指标权重子模块,构造对访问请求风险值有较高灵敏度的风险评估模块.仿真实验结果表明,云平台动态风险访问控制模型具有较好的有效性和可行性,并且与其他模型相比,具有较好的实时性和自适应性.

关键词: 风险评估, 访问控制, 事件推演, 云平台

Abstract:

As the risk access control model can not match rules dynamically and the risk values are insensitive to access requests, a cloud platform dynamic risk access control model(CDRAC) is proposed. First, the attribute based access control(ABCA) is improved with the event calculus(EC), and the dynamic rule matching module is constructed in the CDRAC. Then, the dynamic risk evaluation index weight distribution sub-module is designed, and the risk assessment module with high sensitivity to access requests is constructed. Experimental results show that the CDRAC has good effectiveness and feasibility, and that it has a better real-time performance and adaptability than other existing models.

Key words: risk assessment, access control, event calculus, cloud platform