浙江大学学报(工学版)  2017, Vol. 51 Issue (12): 2332-2340    DOI: 10.3785/j.issn.1008-973X.2017.12.004
刘敖迪, 王娜, 刘明聪
信息工程大学, 数学工程与先进计算国家重点实验室, 河南 郑州 450001
Access control mechanism for cloud composite service with policy attribute negotiation
LIU Ao-di, WANG Na, LIU Ming-cong
Information Engineering University, State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou 450001, China
APoAN (access control mechanism based on policy attribute negotiation) was proposed for cloud composite servic. In APoAN, an authorization relation between service components was described at the attribute level that can meet the dynamic, flexible, point-to-point interaction characterisics in cloud environment. The mechanism used policy attribute negotiation to achieve interactive process of access control, which reduced the disclosure of security information within the service and effectively protected the user's privacy. The mechanism can ensure the consistent presentation of different service components policies in global composite service. A policy negotiation algorithm was designed based on historical information. The negotiation process was optimized and the efficiency of negotiation was improved by synchronizing high frequency negotiation policy, storing history information of negotiation and calculating the cost of attributes disclosure. Finally, the simulation results show the feasibility and efficiency of the proposed mechanism.

收稿日期: 2016-10-13 出版日期: 2017-11-22
通讯作者: 王娜,女,副教授     E-mail:
作者简介: 刘敖迪(1992-),男,博士生,从事云计算安全、网络信息安全研究
刘敖迪, 王娜, 刘明聪. 基于策略属性协商的云间组合服务访问控制机制[J]. 浙江大学学报(工学版), 2017, 51(12): 2332-2340.

LIU Ao-di, WANG Na, LIU Ming-cong. Access control mechanism for cloud composite service with policy attribute negotiation. JOURNAL OF ZHEJIANG UNIVERSITY (ENGINEERING SCIENCE), 2017, 51(12): 2332-2340.


