论文部分内容阅读
提出了一种新的基于描述逻辑的形式化表示方法,将组成基于角色的访问控制(RBAC,Role-Based Access Control)模型的集合和关系分别用描述逻辑中的概念和角色表示,并且在基本的描述逻辑语言上引入了可以表示角色的复合关系和包含关系的符号,从而形式化表示出了RBAC与角色继承有关的一些关键性质和约束条件,如角色层次关系(RH,Role Hierarchy)传递性、用户角色分配关系(UA,User-Role Assignment)的继承性和权限角色分配关系(PA,Permission-Role Assignment)的继承性,以及RBAC中的静态职权分离约束和动态职权分离约束等.通过形式化地表示RBAC的继承关系及约束条件,利用描述逻辑本身的推理机制可以限制不符合访问控制策略的继承关系产生.
A new method of formal representation based on description logic is proposed. The set and relationship of RBAC (Role-Based Access Control) model are represented respectively by concepts and roles in description logic, Describes some key properties and constraints related to role inheritance, such as RH (Role Hierarchy) transitivity, which is formally expressed in the description logic language which can represent the compound relationship of the roles and the symbol of inclusion relationship. , Inheritance of User-Role Assignment (UA) and inheritance of Permission-Role Assignment (PA), separation of static authority and separation of dynamic authority in RBAC, etc. By the formal Representation of RBAC succession relations and constraints, the use of the logic of the description of the logic itself can limit the non-compliance with access control policy inheritance relationship.