对电子飞行包(EFB)系统的安全访问控制问题进行了研究。提出了一种基于风险评估的EFB系统访问控制模型,设计了包含上下文模块、访问控制模块、风险评估模块的模型框架,定义了模型的元素和控制流程,通过上下文信息模块和基于D-S证据理论的风险评估模块为访问控制决策提供依据,采用基于阈值比较的访问控制决策算法和访问控制策略动态调整机制实现访问控制决策。实验结果证明该模型能有效满足EFB系统的安全访问需求。
This paper studies the secure access control issues of electronic flight bag (EFB) systems. A risk assessment based access control model for EFB systems is proposed. An access control model framework with the modules of context, access control and risk assessment is given, and the elements and the control procedure of the model are defined. The parameters for access control decision can be obtained through the context module and the Dempster-Shafer theory based risk assessment module. Then the access control decision can be achieved through the threshold comparison based access control decision algorithm and the dynamic adjustment mechanism of access control strategies. The experimental result demonstrates that this access control model can effectively meet the secure access requirements of EFB systems.