文档介绍:网格环境下访问控制策略的研究与设计
摘要
随着世界信息化程度的逐步发展,原有的单一计算机的计算能力,存贮资源的能力和其他数据交换等诸多能力以远远更不上社会的发展。为了达到以上的要求,网格技术就应运而生了。
访问控制是限制某个对象(用户或角色)对资源访问或使用,它防止资源被某个对象的越权操作,它是对资源最为重要安全的管理,因此访问控制在在网格技术中是比较重要的一部分。
本文将综述国内外的网格发展情况,归纳网格特点及优势;简述Globus平台环境,叙述其特点、结构;总结现有的访问控制策略,介绍自主访问策略,强制访问策略等策略;重点介绍基于基于角色访问控制策略的模型、特点和在网格环境下的优势和不足;跟据网格环境的要求拓展基于角色访问控制策略,添加了基于任务的访问控制策略中的授权步概念,提出了E-RBAC;在Globus ToolKit 平台下,采用Java 语言实现E-RBAC的访问策略;在理论上与其他访问策略比较,E-RBAC访问策略更为灵活,更能增加网格资源的利用率。
关键字:网格;访问控制;RBAC;授权步
RESEARCH AND DESIGN OF ACCESS CONTROL STRATEGY IN GRID
Abstract
With the world the extent of the progressive development of information technology, the original puter'puting power, storage resources, capabilities and data exchange, and many other is far less on the ability to keep pace with the social development. To achieve the above requirements, grid technology is brought up.
Access control is that an object (user or role) is restricted to access or use, which prevent resources from being an object of ultra vires action, which is the most important security resource management, so access control is more important part in grid
This paper will survey the development of domestic and international grid environmental, sum up the characteristics and advantages of the grid. Globus platform is briefly describing its characteristics, structure. Summarize the existing access control, introducing Discretionary Access Control, Mandatory Access Control and other strategies. Emphasize role-based access control model, characteristics, and in the grid environment, the advantages and disadvantages. According to the grid environmental requirements I expand strategy basing on the role-based access control, add the authorization step concept from the task-based access control, bring up the E-RBAC. On the Globus ToolKit platform, the E-RBAC can be put into practice by using Java language. compared with the other in theory, the E-RBAC is more flexible and can increase appropriation rate of the grid resource.
Key