上海交通大学学报(自然版) ›› 2013, Vol. 47 ›› Issue (04): 579-583.

• 自动化技术、计算机技术 • 上一篇    下一篇

基于二进制序列集合的策略合成代数框架

刘晨燕1,2,潘理1,2,訾小超2   

  1. (1.上海交通大学 电子信息与电气工程学院,上海 200240;2.上海市信息安全综合管理技术研究重点实验室,上海 200240)
  • 收稿日期:2012-06-26 出版日期:2013-04-28 发布日期:2013-04-28
  • 基金资助:

    国家重点基础研究发展规划(973)项目(2013CB329603),国家自然科学基金资助项目(60903191),上海市自然基金课题信息 (11ZR1418500)

A Binary-String-Set-Based Algebraic Framework for Policy Composition

 LIU  Chen-Yan-1, 2 , PAN  Li-1, 2 , ZI  Xiao-Chao-2   

  1. (1. School of Electronic, Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai 200240, China; 2. Shanghai Key Laboratory of Information Security Synthesis Management Technique Research, Shanghai 200240, China)  
  • Received:2012-06-26 Online:2013-04-28 Published:2013-04-28

摘要:   从代数建模和实现机制相融合的角度出发,提出了一种基于二进制序列集合的策略合成代数框架.首先通过定义二进制序列集合元素及构造集合运算规则,将策略抽象成逻辑模型.然后针对多终端二进制决策树(MTBDD)的逻辑建模机制中存在的编码次序敏感以及规则冗余问题,提出了基于二进制序列的移位合并算法.最后推导基于二进制序列的合成语义算子,建立该代数框架.通过时间复杂性分析和仿真实验,验证了该框架的有效性,其合成性能优于基于MTBDD策略树的合成机制.    

关键词: 访问控制, 属性, 策略合成

Abstract: A new algebraic framework was proposed for merging the algebraic model with the implementation mechanism. In this framework, the policy is converted into logic pattern by defining new binary string/binary string set and constructing a new set of operation rules. Depending on that, an algorithm named rotate-combination is issued to solve the problem of order-sensitivity and rule-redundancy in MTBDD mechanism. By deriving the semantic operators and formulating the policies composition as expressions of the algebra, a new model was set. Furthermore, an analysis of the time complexity and simulation results were given to demonstrate the effectiveness of the framework, and its performance is better than that of the MTBDD-based mechanism.  

Key words: access control, attribute, policy composition

中图分类号: