高级检索

    基于可信平台的一种访问控制策略框架——TXACML

    TXACML—An Access Control Policy Framework Based on Trusted Platform

    • 摘要: 根据可信平台访问控制需求,提出一个可信平台属性分类规则,定义属性评估函数,可以实现可信平台数据安全分发和访问.同时针对XACML现有的策略合成算法不能有效满足可信平台自动方策略复合需求,设计了一个基于平台可信度的策略合成算法,该算法可以使策略的优先级和可信度保持一致,实现自动方策略复合.在此基础上,进一步对XACML实施扩展,形成可信平台策略语言框架TXACML(XACML based on trusted platform).采取TXACML对一个实例给出了策略描述和策略合成过程,验证了TXACML的有效性.

       

      Abstract: Trusted platform based on trusted hardware has been used widely in the access control of content distributed environment. To express trusted platform policy by a standard language, XACML is introduced to trusted platform. But XACML does not provide attribute evaluation function for platform, which can not meet the access control requirement of the trusted platform. In this paper, the access control requirement is divided into data distribution and access on the trusted platform. Then based on this analysis, a classification rule for trusted platform attribute and the corresponding attribute evaluation function are proposed, which can be used in the safe distribution and access of trusted platform data. In XACML combining algorithms, an administrative center is always needed, which could not be considered conforming to the policy combining requirement of the trusted platform. A policy combining algorithm based on trusted degree of the platform is presented to combine the policy of independent parties, which makes the policy preference be in conformance with trusted degree of the platform. Furthermore, based on the evaluation function and combining algorithm, XACML is extended to form a policy language framework based on trusted platform-TXACML. The policy description and combining process for an instance are given subsequently, proving the validity of TXACML.

       

    /

    返回文章
    返回