细粒度基于传递功能的约束委托模型

Fine-Grained Constrained Delegation Model Based on Transferable Capability

  • 摘要: 为保证系统的安全性并体现委托的灵活性,引入了与角色相互独立、可转授委托人全部或部分权限的传递功能概念,提出了一种细粒度基于传递功能的约束委托模型.该模型支持以传递功能为委托单位、细粒度、约束限制的多步委托.采用构造和规约两方法对委托约束的一致性进行了论证.理论分析及委托实例验证了模型的安全性与灵活性

     

    Abstract: In order to ensure system security and reflect flexibility in delegations, a fine-grained constrained delegation model was proposed by introducing the transferable capability which was independent of the role concept and could transfer all or part of delegators’ permissions. The model can support the fine-grained, constrained and multi-step delegations. Two methods of construction and reduction were adopted to verify the consistency of delegation constraints. Theoretical analyses and delegation examples showed that the model is secure and flexible

     

/

返回文章
返回