• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2007, Vol. 29 ›› Issue (3): 23-26.

• 论文 • 上一篇    下一篇

基于Clark-Wilson的属性证书授权模型

孟洋 徐向阳 黄海   

  • 出版日期:2007-03-01 发布日期:2010-05-30

  • Online:2007-03-01 Published:2010-05-30

摘要:

本文采用Clark-Wilson完整型模型,使用属性证书作为权限传递的载体,结合授权管理基础设施(PMI)实现基于角色的授权模型,并提出一种形式化描述架构,描述权限、证书和相关的授权;基于语义的演算过程对给定的属性证书集和撤销证书集可以验证某种权限是否有效;采用Alloy形式化语言来定义模型,并且给出描述扩展Clark-Wilson的方法。

关键词: 证书 授权模型 Clark-Wilson

Abstract:

The Clark-Wilson-based integrity model is introduced, and the privilege management infrastructure is studied,and a role-based authorization model is implemented with attribute certificates,and then a formal description framework is put forward to describe privilege,certificates and interrelated author  ization.The semantics-based calculation can verify privilege by some appointed attribute certificate sets and revocation certificate sets.Finally,the model is defined with the Alloy formal language,and a method of expanding the Clark-Wilson model is also presented.

Key words: ceitificate;authorization model;Clark-Wilson