西安交通大学电子与信息工程学院,西安,710049
网络首发:2009-06-10,
纸质出版:2009
移动端阅览
官尚元, 伍卫国, 董小社, 等. 分布式环境中高效信任管理的研究[J]. 西安交通大学学报, 2009,43(6):15-19.
Research on Efficient Trust Management in Distributed Environments[J]. 2009, 43(6): 15-19.
针对分布式环境中信任管理缺乏统一定义和一致性验证算法效率较低等问题
给出了信任管理的形式化定义.信任管理为六元组
包括可数的主体集、信任类型集、信任属性集、上下文集
以及主体之间存在的信任关系和定义在信任关系上的且封闭于此关系的函数.同时
讨论了形式化定义与描述性定义之间的关系
由此提出了高效的信任管理模型NUMEN.模型的一致性验证算法基于格不动点理论
其时间复杂度和空间复杂度与授权证书集的势n有关
均为O(n).实验结果表明
NUMEN以较小的开销能够获取较高的安全性
其一致性验证算法优于SPKI/SDSI 和KeyNote模型
并得出了授权证书数和权限委托节点数是影响系统运行时间的关键因素的结论.
Many trust management(TM)systems have been proposed
but some issues still remain to be addressed
e.g. there is no consensus on the definition of TM in the literature
and algorithms for proof of compliance are inefficient. To address these problems
a formal definition of TM is proposed in this paper
which is composed of a set of countable principals
a set of trust classes
a set of trust attributes
a set of contexts
a set of trust relationships and a set of rules. The relationship between the formal TM and the descriptive TM is discussed. Based on the formal definition of TM
an efficient TM
called NUMEN
is presented
and the algorithm for PoC is based on the lattice-theoretical fix-point theorem. The time complexity and the space complexity of the algorithm are both O(n)where n is the cardinality of the set of authorization credentials. Experimental results show that NUMEN can effectively protect sensitive resources at the cost of little performance of systems
and the PoC algorithm for NUMEN is more efficient than those for the existing TM systems such as SKPI/SDSI and KeyNote. It is observed that the numbers of authorization brokers and of delegation credentials are crucial factors in determining the runtime.
TOLONE W, AHN G J, PAI T. Access control in collaborative systems [J]. ACM Computing Surveys,2005, 37(1): 29-41.
BLAZE M, FEIGENBAUM J, LACY J. Decentralized trust management [C]∥IEEE Symposium on Security and Privacy. Los Alamitos, NJ, USA: IEEE Computer Society, 1996: 164-173.
BLAZE M, IOANNIDIS J, KEROMYTIS A D. Experience with the KeyNote trust management system: applications and future directions, iTrust 2003 [M]∥LNCS 2692. Berlin, Germany: Springer-Verlag, 2003: 284-300.
CHU Y H, FEIGENBAUM J, MACCHIA B L, et al. REFEREE: trust management for web applications [J]. World Wide Web Journal, 1997, 2(3): 127-139.
LI N, MITCHELL J C. Understanding SPKI/SDSI using first-order logic [J]. International Journal of Information Security, 2006, 5(1): 48-64.
WEEKS S. Understanding trust management systems [C]∥IEEE Symposium on Security and Privacy. Los Alamitos, NJ, USA: IEEE Computer Society, 2001: 94-105.
JOSANG A, ISMAIL R, BOYD C. A survey of trust and reputation systems for online service provision [J]. Decision Support Systems, 2007, 43(5):618-644.
LI N, WINSBOROUGH W H, MITCHELL J C. Distributed credential chain discovery in trust management [J]. Journal of Computer Security, 2003, 11(1): 35-86.
0
浏览量
4
下载量
2
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621