|国家科技期刊平台
首页|期刊导航|信息安全研究|基于角色和属性的零信任访问控制模型研究

基于角色和属性的零信任访问控制模型研究OACSTPCD

Research on Zero Trust Access Control Model Based on Role and Attribute

中文摘要英文摘要

面对网络中大量涌现的安全威胁,传统访问控制模型暴露出权限分配动态性差、面对新威胁敏感度低以及资源分配复杂度高的问题.针对上述问题,提出一种基于角色和属性的零信任访问控制模型,模型使用逻辑回归的方法对访问主体进行信任评估,实现对访问主体属性高敏感度的访问控制,并采用一种全新的资源决策树,在实现访问控制更细粒度安全性的同时,降低了对资源权限分配的时间复杂度.最后,通过在典型应用场景下对模型进行验证,表明该模型在权限动态分配方面明显优于传统访问控制模型.

In the face of many security threats in the network,the traditional access control model is increasingly exposed to the problems of poor dynamics of permission allocation,low sensitivity to new threats,and high complexity of resource allocation.This paper proposed a zero trust access control model based on role and attribute to address the above problems.The model used a logistic regression approach to trust assessment of access subjects to achieve access control with high sensitivity to access subject attribute,and adopted a new resource decision tree,which reduced the time complexity of resource permission assignment while achieving finer-grained security for access control.Finally,verifying the model in this paper under typical application scenarios showed that the model was significantly better than the traditional access control model in terms of dynamic assignment of permissions.

许盛伟;田宇;邓烨;刘昌赫;刘家兴

北京电子科技学院信息安全研究所 北京 100070北京电子科技学院网络空间安全系 北京 100070北京电子科技学院密码科学与技术系 北京 100070

计算机与自动化

零信任角色属性访问控制资源决策树

zero trustroleattributeaccess controlresource decision tree

《信息安全研究》 2024 (003)

241-247 / 7

国家重点研发计划项目(2022YFB3104402);中央高校基本科研业务费专项资金项目(328202221)

10.12379/j.issn.2096-1057.2024.03.07

评论