针对静态职责分离策略与可用策略并存时由于其互斥的需求可能引发策略非一致性冲突问题,提出了一套基于优先级的冲突消解方法.在综合考虑策略自身严格性以及对整个策略集合的影响力等因素下,提出了一种策略优先级计算方法.定义了策略的自身可满足频率和加权冲突面积这两个概念,分别表示策略的自身严格性和该策略对整个策略集合的影响力.在此基础上,根据不同的策略目标,给出了两种基于优先级的策略消解算法:最小代价方法和字典编辑优选方法.实验结果表明,在静态职责分离和可用策略的数量规模不大的情况下,基于优先级的冲突消解方法可以有效地解决策略非一致性冲突问题.
Inconsistency conflicts may arise between static separation-of-duty and availability pol- icies due to their opposite focuses. This paper provides a priority-based approach to resolve policy inconsistency conflicts. Considering the facts of the policy strictness and its influence on the whole policy set, we propose a method to calculate the policy priority. The concepts of self-satis- fied frequency and weighted conflict area are introduced to denote the policy strictness and its influence on the whole policy set respectively. Based on these two concepts, two algorithms for inconsistency resolution are presented according to different objectives of the policies: minimum cost algorithm and lexicographical inference algorithm. The experimental results show that the proposed priority-based conflict resolution approach scales reasonably well when the number of static separation-of-duty and availability policies is not very large.