首页|基于EBPN模型的电子商务结构化安全验证方法

基于EBPN模型的电子商务结构化安全验证方法

Electronic Commerce Structured Security Verification Method Based on EBPN Model

扫码查看
电子商务借助互联网中app等形式作为媒介,打破传统的面对面交易体系,使系统变得更复杂,以至易产生更多恶意行为,这些恶意行为可能来自用户,商家或第三方平台等.第三方支付平台的加入使程序逻辑设计更复杂,更多结构化问题产生.为此,首先,根据基于Petri网的电子商务业务流程网模型,对电子商务系统进行建模推演,提出了电子商务业务流程关键网模型.其次,根据基于角色访问控制策略中的基数约束和职责分离进行改进,提出了电子商务模型中的行为分离和变迁约束.通过对序列发生的充分性进行补充,完善在Petri网模型中变迁序列发射的充分必要条件,为构建线性不等式提供了条件.最后通过构造线性规划的方法对网模型系统中的变迁约束和行为分离进行求解,进而验证系统的结构化安全性.
With the help of apps and other forms on the Internet as a medium,e-commerce breaks the traditional face-to-face transaction system,making the system more complex and prone to more malicious behaviors,which may come from users,merchants or third-party platforms.The addition of the third-party payment platform makes the program logic design more complicated and more structural problems arise.Therefore,first of all,according to e-commerce business process network model based on the Petri net,the e-commerce system is modeled,and the e-commerce business process critical network model is proposed.Secondly,according to cardinality of constraints and separation of duties based on the role access control strategy for improvement,the separation of action and constraints of transition in the e-commerce system is put forward.By supplementing the sufficiency of sequence generation,the sufficient and necessary conditions of transition sequence emission in Petri net model are perfected,which provides the conditions for constructing linear inequalities.Finally,the constraints of transition and separation of action in the network model system are solved by constructing linear programming method,and then the structural security of the system is verified.

electronic commercePetri netcardinality of constraintinteger linear programmingstructural security

宋浩天、刘伟

展开 >

山东科技大学 计算机科学与工程学院,山东 青岛 266590

电子商务 Petri网 基数约束 整数线性规划 结构化安全

山东省教育教学研究重点课题

2023JXZ001

2024

计算机技术与发展
陕西省计算机学会

计算机技术与发展

CSTPCD
影响因子:0.621
ISSN:1673-629X
年,卷(期):2024.34(10)