Chinese Wall下的委托要求委托过程不但满足常见的委托约束条件外,还需要满足Chinese wall Security Policy(CWSP)。现有的委托模型很少关注CWSP下的委托。分析了CWSP下委托的需求和特殊性。在对现有委托模型扩充的基础上,定义了冲突角色和角色激活历史来体现CWSP,给出了CWSP下进行委托需要满足的关系。提出了基于角色的CWSP下委托的方法与步骤。给出了系统实现框架和主要算法。
Delegation with "Chinese Wall" must satisfy not only regular delegation constraints,but Chinese Wall Security Policy (CWSP) as well.Existing delegation models pay little attentions to this field.This paper analyzes requirements and specificities of delegation with CWSP.Based on the extension of existing delegation models, this paper defines conflict role and role activa- tion history to describe CWSP, and gives relations to restrict delegation with CWSP.Methods and steps of delegation are proposed with CWSP based on role.This paper proposes implementation architecture and some main algorithms.