本体是共享概念模型的形式化规范说明,是一种能在语义和知识层次上描述信息系统概念模型的建模工具,为解决多域环境中的安全互操作提供了一种新的方法.使用本体及其描述语言,对基于角色的访问控制策略进行了描述,形成一个概念和属性的公理集合(TBox),并采用ALCN(含有个数限制和补算子的描述逻辑语言)对TBox进行形式化的描述.利用域间角色映射方法来解决多域访问控制策略的集成.使用基于规则的推理技术,定义多域访问控制中的一系列推理规则,实现访问控制领域的推理.基于前述方法实现了OntoAC系统,实验结果表明该方法是有效的.
Ontology is a formal, explicit specification of a shared conceptualization. It is a modeling tool that can describe the concept model of information system on the semantic and knowledge level. It can provide a new way to solve the multi-domain secure interoperation problem. We use ontology and its description language to describe the access control policy, and create an axiom aggregation (TBox) including concepts and properties. We use the ALCN (a type of description logic including the number restrictions and negation concepts) to formalize the TBox. We also use the role translation method to integrate multi-domain access control policies. Through the rule-based reasoning technology, we define a serial of reasoning rules that can be enforced in multi-domain access control environment. Finally, we develop the OntoAC system according to the methods mentioned above, and the results show that the methods are effective.