支持协作的基于属性访问控制
ooperative Attribute-Based Access Control
本文介绍了一种为企业计算系统设计的 支持协作的基于属性访问控制机制。该系统中用户被划分为不同的群体,且都关联着不同的属性。只有来自相同群体的成员能结合其属性私钥以组成一个关于更大属性并集的密钥,而来自不同群体的成员则无法进行该操作。通过形成的属性并集,用户们就能够生成相应的签名。本文给出了该机制的一种有效的设计,正式证明了其安全性并测试了原型方案的实用性。
In this paper we introduce a cooperative attribute-based access control mechanism, which is specifically designed for enterprise computing system. In our system, users are divided into different groups and they are affiliated with different attributes. Only members from the same group can combine their signing keys to form the signing key of a larger union set of attributes, but users from different groups cannot make it. With the union of the attributes, users can generate a signature which can be used to grant access right to the enterprise cloud system. The applications range from private cloud of a small and medium enterprise (SME) to a large public cloud of electronic healthcare system. We give an efficient design of this mechanism, formally prove its security and implement the prototype of our scheme.
许力、黄欣沂、Joseph K. Liu、伍玮、李梦婷
计算技术、计算机技术
访问控制云计算签名基于属性.
Access ControlCloud ComputingSignatureAttribute-based.
许力,黄欣沂,Joseph K. Liu,伍玮,李梦婷.支持协作的基于属性访问控制[EB/OL].(2015-01-23)[2025-08-02].http://www.paper.edu.cn/releasepaper/content/201501-408.点此复制
评论