给出一种基于角色代理技术的虚拟组织访问控制模型,与同类研究成果相比,在不降低自治域的安全管理效率的情况下,能够实现虚拟组织的细粒度授权和确保自治域的安全策略不被破坏.该模型的一个原型系统已经实现,并通过一个基于网格的低成本电子政务平台中的实例进行了验证.
In a service grid, the efficiency of security administration and security assurance of virtual organizations and autonomous domains are challenging issues. Access control is usually implemented through mapping virtual organization users to autonomous domain's local users, which reduces the efficiency of security administration and bears the risk of violating security policy of these domains applying RBAC model. A role-based delegation access control model for virtual organizations is proposed in the paper, which has little effect on security administration efficiency, and does not violate autonomous domain's security policy. It is implemented and validated in a grid-based e-Government platform.