论文部分内容阅读
针对云平台各访问控制点的访问控制机制难以有效联动问题,该文提出了全系统一体的访问控制保障模型。首先,形式化定义了访问请求的等价关系及支撑关系,对访问请求的本质进行了描述;其次,给出了基于模型的访问控制保障算法,形式化证明了算法能够实现可信的访问控制请求传递;最后,从云平台的网络层、云应用层和操作系统核心层给出了模型的工程实施方法。结果表明:通过访问请求语义的传递,模型实现了全系统访问控制机制的联动,保证了访问请求信息的可信传递。
Aiming at the problem that the access control mechanisms of access control points in the cloud platform are difficult to be effectively linked, a system-wide access control guarantee model is proposed. First of all, formally defines the equivalence relation and support relationship of the access request and describes the essence of the access request. Secondly, the model-based access control security algorithm is given. The formal proof shows that the algorithm can achieve the trusted access control Request delivery; Finally, from the cloud platform network layer, the cloud application layer and the operating system core layer gives the model of the project implementation method. The results show that through the transfer of access request semantics, the model realizes the linkage of system-wide access control mechanism and ensures the trusted delivery of access request information.