网格安全基础设施(GSI)解决了身份鉴别、保密性和完整性问题,却难以有效地解决访问控制问题,传统的访问控制模型也不能很好地满足网格的安全需求。为此,提出了一种基于任务的计算网格访问控制模型。该模型通过定义授权步和任务状态及系统条件约束,能动态地控制主体访问资源的权限,具有较好的通用性、灵活性和可扩展性,并已在计算网格实验平台中得到了实现。
The grid security infrastracture (GSI) is emerged for identify authentification, data confidentiality and integrity, but can not solute problems about access control well. Traditional model of access control can not satify security requerments of grid either. This paper described a task-based access control model for computing grid. The model defined authorization steps, task status and system conditions, and pemissions could be dynamically controled. This model was enforced in computing grid experimental platform, and proved to be universal, flexible and extendable.