Font Size: a A A

Research On Policy Conflicts Solution Of Role-based Access Control Model

Posted on:2008-10-07Degree:MasterType:Thesis
Country:ChinaCandidate:L YangFull Text:PDF
GTID:2178360272467582Subject:Computer application technology
Abstract/Summary:PDF Full Text Request
Multi-domain secure interoperation needs an integrated, cooperative and uniform secure management. The solution of the conflicts on interoperation is a base of Multi-domain integration. Ontology is a formal, explicit specification of a shared conceptualization. It is a modeling tool that can describe the concept model of information system on the semantic and sciential level. With the help of Ontology, entites and policies in domains which is supported by RBAC model are described and controlled. For the goal of secure integration , ontology reasoning method is taken for solution of conflicts.A method for reasoning on SWRL-enabled ontology is proposed. SWRL is designed to be the rule language of the Semantic Web. For its undecidability, we introduce a decidable variant of SWRL, DL-safe rules. Our approach is to transform SWRL rules into DL-safe ones to make it decidable. To an OWL-DL knowledge base KB and a program P, the goal is to find a common model ofπ(KB) and P. With the goal transformed into an ABox, we can deal with it by detecting the consistency of the result ABox using Tableau method.We use Description Logic for the building of Ontology knowledge base on RBAC model. We define concepts in Ontology for entities in domain. The policy rule is described by Semantic Web Rule Language(SWRL) . We add modal operator to Description Logic to describe Authorization policies and Obligation policies.We study on conflicts in Multi-domain and sort them generally. The causation of conflicts are analyzed. We use reasoning method of SWRL-enabled Ontology to detect conflicts. Corresponding solutions are given to different causation of conflicts.Finally, a simulating system of solution on conflicts in the multi-domains supported by RBAC model is designed and implemented. In the system, the access control policies of the single domain are defined in the assertional(ABox). The system can load TBox, policy base and ABox. After it, we can reasoning ontology for the integration to detect and solute conflicts.
Keywords/Search Tags:Distributed system, Multi-domain, Role-based Access control, policy conflict, Ontology, Description Logic
PDF Full Text Request
Related items