LI Rui-xuan, HU Jin-wei, TANG Zhuo, et al. R~2BAC:a risk-based multi-domain secure interoperation model[J]. 2008, (10): 58-69.DOI:
R2BAC:基于风险的多自治域安全互操作模型
摘要
在基于角色访问控制模型的基础上
提出了一种基于风险的多自治域安全互操作模型——R2BAC。R2BAC采用了灵活的互操作关系建立机制
无需第三方实体的参与。将建立互操作问题转换为优化问题
在保证安全性的前提下取得理想的互操作能力。尽管分布式环境中自治域可随时加入和离开
R2BAC保证了互操作关系的创建与撤消能适应这种动态性。R2BAC引进了风险管理机制
提供了细粒度的授权控制;具有实时监控用户行为、调整用户权限的能力。
Abstract
R2BAC
a risk enabled role—based model for multi-domain secure interoperation
was proposed to adapt to the dynamics of distributed environments.R2BAC employs a flexible mechanism to establish interoperation between domains
eliminating the need of a trusted third-party.It translates the problem of interoperation establishment into an op-timality problem
thus achieving optimal interoperability on the premise of domains’ security.The creation and abolish-ment of interoperation relationships in R2BAC are in accord with the dynamics of distributed environments
where do-mains join and leave in an ad hoc manner.Furthermore
R2BAC incorporates risk management methods
leading to at least two advantages.First
a fine-grained authorization mechanism is enabled;second
it is possible to monitor users’ behaviors and adjust their permission sets in a real time manner.