引用本文:韩将,张振峰,刘雨果,胡可欣,何双羽.面向跨信任域互联网场景的拜占庭容错访问控制架构.软件学报,2025,36(9):4223-4240
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 917次   下载 1990 本文二维码信息
码上扫一扫!
分享到: 微信 更多
面向跨信任域互联网场景的拜占庭容错访问控制架构
韩将1,2, 张振峰2, 刘雨果1,2, 胡可欣2, 何双羽2
1.中国科学院大学, 北京 100049;2.中国科学院 软件研究所 可信计算与信息保障实验室, 北京 100190
摘要:
工业界现用的访问权限控制技术愈来愈难以应对广域互联网场景下部署的分布式系统的访问控制问题, 特别是跨多个信任域部署的大型信息系统在地理分布上不断分散化, 造成防护弱点不断增加. 基于共识的访问控制策略共享技术能够使跨信任域部署的访问控制节点安全快速地达成一致决策. 首先提出面向多节点的基于共识的访问权限控制模型, 提出强安全高性能的访问控制引擎共识算法Super-Dumbo. 该算法突破Dumbo2共识协议的性能瓶颈, 优化消息广播、随机掷币、共识算法设计等关键步骤的设计, 减少数字签名验证等计算开销、有效提升带宽利用率, 从而在吞吐量和延迟时间等性能方面取得大幅提升, 满足CBAC访问控制模型对底层共识算法低延迟、大吞吐量的性能要求.
关键词:  分布式访问控制  拜占庭容错  异步共识协议  基于共识的访问控制
DOI:10.13328/j.cnki.jos.007274
分类号:TP309
基金项目:国家重点研发计划(2022YFB2701600)
Access Control Structure Based on Byzantine Fault Tolerance in Cross-trust-domain Internet Scenarios
HAN Jiang1,2, ZHANG Zhen-Feng2, LIU Yu-Guo1,2, HU Ke-Xin2, HE Shuang-Yu2
1.University of Chinese Academy of Sciences, Beijing 100049, China;2.Trusted Computing and Information Assurance Laboratory, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
Abstract:
In the industrial field, currently used access permission control technologies are increasingly struggling to address access control issues of distributed systems deployed in wide-area internet scenarios. This situation is particularly exacerbated when dealing with large-scale information systems distributed across multiple trust domains, thereby engendering an escalating proliferation of vulnerabilities. Consensus-based access control policy sharing technologies can facilitate the secure and expeditious attainment of consensus decisions among access control nodes deployed across trust domains. This study first proposes a consensus-based access permission control model for multiple nodes and presents the Super-Dumbo consensus algorithm for access control engines, which features robust security and high performance. Super-Dumbo surmounts the performance bottlenecks of Dumbo2 by optimizing the design of key steps encompassing message broadcasting, random coin toss procedures, and consensus algorithm constructs. Notably, it reduces computational overhead such as digital signature verification, thereby effectively enhancing bandwidth utilization. This achieves a substantial improvement in performance metrics, such as throughput and latency, aligning seamlessly with the performance prerequisites of the CBAC access control model, which demands low latency and high throughput from the underlying consensus algorithm.
Key words:  distributed access control  Byzantine fault tolerance  asynchronous consensus protocol  consensus-based access control