在开放式信息系统中,访问控制是保证信息系统安全的一项重要措施。传统访问控制模型在授权过程中没有考虑主体的信任度和权限集合划分等问题。文中引入模糊逻辑的思想,提出了基于信任授权的模糊访问控制模型.运用模糊综合评判法计算出主体在开放式信息系统中的信任度,并建立模糊控制规则,通过模糊判决自动授予主体相应的权限。使其能够更好的满足开放式信息系统中访问控制的要求。
In open information system, access control is an important measure that assures the information system security. Traditional access control model hardly consider the issue of subjects' trust worthiness and privilege partition. Introducing the idea of fuzzy logic,this paper advances Trust-authorization-based fuzzy access control model and exerts fuzzy synthetic judgment method to calculate subjects' trust worthiness, establishes fuzzy control rules, automatically authorizes subjects' relevant privilege by fuzzy adjudging, which can satisfy requirements of open information system access control.