信息安全研究 ›› 2021, Vol. 7 ›› Issue (2): 184-189.

• 技术应用 • 上一篇    下一篇

一种基于CPK角色访问控制的方案

陈亚茹   

  1. 河南工业贸易职业学院
  • 收稿日期:2021-02-09 出版日期:2021-02-05 发布日期:2021-02-09
  • 通讯作者: 陈亚茹
  • 作者简介:陈亚茹 硕士,助教,主要研究方向为信息安全、大数据. 642200814@qq.com

A Scheme Based on CPK Role Access Control

  • Received:2021-02-09 Online:2021-02-05 Published:2021-02-09

摘要: 针对非法用户越权访问公司内部数据引起的安全问题,提出了组合公钥(CPK)和角色访问控制(RBAC)相结合的改进模型.通过保留RBAC96模型中继承约束关系的基础上,去除RBAC97模型中继承关系的复杂度,以及引入用户组概念.其中每个密钥代表不同的权限,同时对密钥赋予相应的用户.不同密钥保护不同的文档,不同用户分配不同的密钥,合法用户只有根据自己密钥权限才可以解密相应的文档,加强了访问控制模型的安全.通过实现测试结果证明,该方案在系统中运行正常,并验证了方案的可行性.

关键词: 组合公钥, 角色访问, 密钥权限, 权限控制, 越权访问

Abstract: For security problems caused by illegal users' unauthorized access to internal data of the company, an improved model of combined public key (CPK) and role access control(RBAC) is proposed. On the basis of preserving the inheritance constraint relationship in RBAC96 model, the complexity of the inheritance relationship in RBAC97 model is removed and the concept of user group is introduced. Introducing user groups and encrypting documents with keys, each of which represents different permissions, the key is also assigned to the corresponding user. Different keys protect different documents, different users assign different keys, legitimate users can only decrypt the corresponding documents according to their key permissions, strengthen the security of access control model. The test results show that the scheme works well in the system and the feasibility of the scheme is verified.

Key words: CPK, role access, key permissions, access control, unauthorized access