自动信任协商是为了解决开放网络环境中陌生实体很难建立信任关系的问题而提出的一种新安全解决方案.本文提出了一种新的信任协商模型,即一种自适应自动信任协商模型AATN,该模型可根据用户的信任度对访问控制策略进行调整,实现了对不同信任度的用户采用不同的访问控制策略,从而在保护隐私的同时提高了信任协商的效率.本文主要分析了自适应信任协商模型的模型框架、自适应协商策略和一致性校验器等关键技术,并通过实验证明了AATN模型能够有效兼顾信任协商中效率和安全两方面的需求.
Automated trust negotiation can realize automated trust establishment between strangers through credential exchange,which provides a new security solution to all open,distributed,dynamic environment.This paper proposes an Adaptive Automated Trust Negotiation(AATN) model,which can dynamically adjust negotiation strategies and access control policies according to trust evaluation,so as to attain balance between negotiation efficiency and privacy protection.The paper describes the framework,an adaptive negotiation strategy,and a compliance checker in AATN.The theoretical analysis and test results reveal that AATN model can realize automated trust negotiation both effectively and securely by using the adaptive negotiation strategy.