J4

• Original Articles • Previous Articles     Next Articles

Improved UCONC authorization decision model for the service grid

GUI Jin-song;CHEN Zhi-gang;DENG Xiao-heng;LIU Li
  

  1. (School of Information Science and Engineering, Central South Univ., Changsha 410083, China)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-06-20 Published:2008-05-30
  • Contact: GUI Jin-song E-mail:jsgui06@163.com

Abstract: To keep free from weak capability of expression of the usage control model based on condition predication decision(UCONC), realize reasonable task assigning between decision component and execution component, and improve concurrent enforcement of independent authorization processes in the service grid, a delegation certification model is proposed to express the decision result in a fine-grained manner, and the UCONC is improved. Delegation certification processing statuses are defined to replace the simple access status. The decision component can make the reasonable delegation certification based on the system status when a request arrives, and also make a decision to change the delegation certification processing status when the system status is changed. This method effectively avoids the fact that the same access requests generate the delegation certification repeatedly, and the delegation certification really reflects actual demands of authorization. In an e-Learning Grid, the improved decision model expresses the authorization policy in a fine-grained manner, and exports reasonable decision results. Various access requests satisfies security requirements of application through the suitable decision and control.

Key words: service grid, authorization decision, delegation certification, UCONC

CLC Number: 

  • TP393