首页|面向政务协同的访问控制模型

面向政务协同的访问控制模型

扫码查看
针对政务协同场景需求复杂多样、人员流动管理困难、数据隐私度高和数据量大的特点,提出面向政务协同办公的访问控制(GBAC)模型.政务协同场景中的访问控制需要实现多部门对同一资源进行不同操作的需求,而现有的主流访问控制技术面临访问控制粒度不够精细和管理维护成本过高的问题,缺乏安全、灵活、精准的访问控制模型.因此,结合政务部门的运行机制,首先,将政府组织结构和行政区划结构融入访问控制模型,并构建政务人员、组织、资源和行政区划的归属关系树;其次,结合政务工作人员所属组织和岗位等属性,构建联合主体,以实现自动化的权限授予和解除;然后,根据组织职能和行政区划等级设计主客体属性匹配策略,从而打通数据壁垒,并提高鉴权效率;最后,引入权限分级思想,为资源设置数据级别和功能级别,以控制主体的访问阈值,从而提高模型灵活性,并进一步保障数据安全.实验结果表明,与基准模型如基于角色的访问控制(RBAC)和基于属性的访问控制(ABAC)相比,GBAC模型的内存消耗大幅减小,访问时延更低.可见,所提模型能安全、高效、灵活地实现政务协同场景下的权限管理.
Access control model for government collaboration
To address characteristics of government collaborative scenarios,such as diverse and complex requirements,difficulty in managing personnel turnover,high data privacy level,and large data size,a Government-Based Access Control(GBAC)model for government collaboration was proposed.Access control in government collaborative scenarios must meet requirement for multiple departments performing different operations to the same resource.The existing access control technologies face issues of inadequate granularity and high maintenance costs,lacking secure,flexible,and precise access control model.Therefore,combining operating mechanisms of government departments,firstly,government organizational structure and administrative division structure were integrated into the access control model,and a belonging relationship tree of government staff,organizations,resources,and administrative divisions was constructed.Secondly,combined with attributes of organizations and positions which the government staff belongs to,a joint subject was constructed to achieve automatic granting and revoking permission.Thirdly,based on organizing functions and administrative division levels,a subject-object attribute matching strategy was designed to break data barriers and improve authentication efficiency.Finally,by introducing idea of permission hierarchy,data levels and functional levels were set for resources to control the access threshold of the subject,which enhanced model flexibility and further ensured data security.Experimental results show that compared with benchmark models such as Role-Based Access Control(RBAC)and Attribute-Based Access Control(ABAC),GBAC model reduces memory consumption and access latency significantly.It can be seen that the proposed model implements access management in government collaborative scenarios securely,effectively and flexibly.

access controlaccess policygovernment collaborationdata sharingRole-Based Access Control(RBAC)Attribute-Based Access Control(ABAC)

赵大燕、何华均、李宇平、张钧波、李天瑞、郑宇

展开 >

西南交通大学 计算机与人工智能学院,成都 611756

北京京东智能城市大数据研究院,北京 100176

京东城市(北京)数字科技有限公司,北京 100176

访问控制 访问策略 政务协同 数据共享 基于角色的访问控制 基于属性的访问控制

2025

计算机应用
中国科学院成都计算机应用研究所

计算机应用

北大核心
影响因子:0.892
ISSN:1001-9081
年,卷(期):2025.45(1)