首页|基于多级身份验证的电力云系统安全访问控制方法

基于多级身份验证的电力云系统安全访问控制方法

扫码查看
常规方法验证用户多级身份时,仅将规则型可信度作为验证依据,导致验证轮数较多,用户访问控制决策时间较长,因此提出基于多级身份验证的电力云系统安全访问控制方法.采集电力云系统访问用户身份合法证据,计算规则型可信度,根据用户状态预测值更新量,计算访问序列可信度.将2种可信度作为验证依据,得到用户多级身份可信度,一次性筛选可信用户,构建安全访问控制模型,管理访问控制策略,判定合法用户访问请求,当访问请求符合策略规则时予以授权,否则不允许授权.选择电力云平台作为测试对象,判定用户的可访问资源,分配读权限、写权限和审计权限,实验结果表明,设计方法面对多条访问控制策略、大量用户访问情况下,都缩短了用户访问控制决策时间.
Secure Access Control Method for Power Cloud System Based on Multi-level Authentication
When the conventional method verifies the user's multi-level identity,only the rule-based credibility is used as the verification basis,which leads to a large number of verification rounds and a long time for user access control decision-making.Therefor,a power cloud system security access control method based on multi-level authentication is proposed.It collects the legal evidence of the user's identity of the power cloud system,calculates the rule-based credibility,and calculates the credibili-ty of the access sequence according to the update amount of the predicted value of the user's state.This paper takes the two kinds of credibility as the verification basis to obtain the user's multi-level identity credibility,screen the trusted users at one time,build a secure access control model,manage the access control policy,determine the legitimate user's access request,and authorize when the access request meets the policy rules,otherwise,authorization is not allowed.The power cloud platform is selected as the test object to determine the user's accessible resources and allocate read permission,write permission and audit permission.The experimental results show that the design method shortens the user's access control decision-making time in the face of multiple access control strategies and a large number of users.

multi-level authenticationpower cloud systemaccess requestaccess control policycredibilityauthorization de-cision

刘俊荣、付鋆、班秋成

展开 >

贵州电网有限责任公司信息中心,贵州,贵阳 550002

多级身份验证 电力云系统 访问请求 访问控制策略 可信度 授权决策

2024

微型电脑应用
上海市微型电脑应用学会

微型电脑应用

CSTPCD
影响因子:0.359
ISSN:1007-757X
年,卷(期):2024.40(11)