• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学 ›› 2010, Vol. 32 ›› Issue (10): 16-19.

• • 上一篇    下一篇

基于安全评估的网格动态访问控制研究

严雷,汤卫民,王宗飞   

  1. (国防科学技术大学计算机学院,湖南 长沙 410073)
  • 收稿日期:2009-03-15 修回日期:2009-06-24 出版日期:2010-09-29 发布日期:2010-09-29
  • 作者简介:严雷(1981),男,陕西大荔人,硕士,助理研究员,研究方向为信息安全和网格计算;汤卫民,高级工程师,研究方向为信息安全;王宗飞,工程师,研究方向为密码学。

Security Evaluation Based Dynamic  Access  Control  for Grid Application

YAN Lei,TANG Wei min,WANG Zong fei   

  1. (School of Computer Science,National University of Defense Technology,Changsha 410073,China)
  • Received:2009-03-15 Revised:2009-06-24 Online:2010-09-29 Published:2010-09-29

摘要:

网格具有异构、动态、多域的特点,这给网格的安全研究带来了新的挑战。网格安全基础设施(GSI)解决了网格环境下的安全认证和安全通信,但没有对访问控制问题足够重视。传统的访问控制方法仅仅从访问资源的角度来解决安全问题。主体操作方式的多样性和用户计算环境的异构性导致了网格环境的动态性和不确定性。当这种动态性对访问主体造成影响时就需要改进访问控制方法,要求访问控制系统能够动态适应网格环境的安全状态变化。针对该问题本文提出了在访问控制前加入安全评估模型(SEMFG),由该模型对访问环境和访问主体进行综合评估,监控网格环境和访问主体的行为,并用评估结果动态指导访问控制。

关键词: 安全评估, 动态, 访问控制, 网格

Abstract:

The emerging Grid infrastructure research presents many challenges due to its inherent heterogeneity,dynamics and multidomain characteristics. GSI,the grid security infrastructure mainly oriented to security authentication and communications,pays insufficient attention to the access control. The traditional access control methods are mainly concerned about the security problems of the provider of resources and miss the protection of the access requesters. The diversity of the operation and user heterogeneous computing environments lead to the dynamic Grid environment and uncertainty.The access control method should be improved when dynamic and uncertain changes of the grid environment affect the access requester. It should be asked to dynamically adapt to the security status changes of the grid environment. In this paper we present a security evaluation model for grid (SEMFG) in order to evaluate the security of the access environment and the requester .Evaluation results can guide the access control.

Key words: security evaluation, dynamic, access control, grid