Dynamic multidimensional space access control method

A dynamic access control and access control technology, applied in the direction of digital data protection, etc., can solve problems such as tampering programs, security risks, and insufficient RBAC model description capabilities

CN109063508AActive Publication Date: 2018-12-21ARMY ENG UNIV OF PLA
2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Publication Date
2018-12-21

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention provides a dynamic multi-dimensional space access control method. The dynamic multi-dimensional space access control method comprises the following steps: 1, constructing a static multi-dimensional space access control model based on role access control, wherein that static multi-dimensional space access control model is a three-tuple< P, Dm, Dc>;, wherein P is a set of decision in access control, Dm is a multi-dimensional space set of subject, object and influence factors, and Dc is a result of access control decision; 2, constructing a dynamic multi-dimensional space access control model based on that static multi-dimensional space access control model, The dynamic multi-dimensional space access control model is used to describe the delegation, distribution and reclamationof rights under the dynamic access control policy by adding a first-order logic M to the static multi-dimensional space access control model and acting on the dynamic access control policy.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention belongs to the technical field of access control, and in particular relates to a dynamic multi-dimensional space access control method. Background technique

[0002] In order to achieve the "separation" of policies and mechanisms in the software system, in the process of implementing the access control system, each stage will try to do the following: In the process of formulating security requirements, it must be independent of the implementation, regardless of the implementation level ; When formulating access control mechanisms based on access control policies, consider and compare multiple access control mechanisms; try to adopt access control mechanisms that can support multiple access control policies. The policy (high level) and the mechanism (low level) are connected through the access control model, so the construction of the access control model determines the relationship between the policy and the mechanism. Whether it is the ...

Examples

Embodiment Construction

[0039] In order to make the object, technical solution and advantages of the present invention more clear, the present invention will be further described in detail below in conjunction with the examples. It should be understood that the specific embodiments described here are only used to explain the present invention, not to limit the present invention.

[0040] Unless the context clearly states otherwise, the number of elements and components in the present invention can exist in a single form or in multiple forms, and the present invention is not limited thereto. Although the steps in the present invention are arranged with labels, they are not used to limit the order of the steps. Unless the order of the steps is clearly stated or the execution of a certain step requires other steps as a basis, the relative order of the steps can be adjusted. It can be understood that the term "and / or" used herein refers to and covers any and all possible combinations of one or more of th...