针对可信网络连接架构中所定义的访问控制粒度粗、对于如何评估访问请求者的可信级别,如何实施授权访问没有定义等问题,提出了根据请求者的行为及其平台计算环境特征评估其信任级别的方法,研究了具有反馈功能的动态访问授权模型,并在构建可信网络连接原型系统的基础上,实现了从连接到授权的接入控制和动态调整.
According to the fact that there are some problems existing in the current trusted connecting network architecture such as network access control is coarse-grained and the lack of definition of how to evaluate the trust level of the access requestor and no authorization methods available,the author proposed a method of evaluating the trust level of the access requestor by its behavior and the states of its computing platform environment,and a dynamic network access control and authorization method was studied.On the basis of implementing,the prototype system of the trusted network connecting,dynamic control and adjustment from the beginning of the connecting phase to the authorization phase of the access requestor's endpoint to the trusted network is carried out.