基于博弈论的可信动态访问控制方案
CSTR:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

TP393

基金项目:

国家重点研发计划(2023YFF0905300); 国家自然科学基金(62272076); 重庆市自然科学基金(CSTB2022NSCQ-MSX0038); 重庆市教委科学技术研究项目(KJQN202200625)


Trustworthy Dynamic Access Control Scheme Based on Game Theory
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    访问控制技术是一种管理用户对资源访问权限的安全机制, 能有效防止未授权访问和资源泄露. 在数字化时代, 如何通过有效的访问控制技术平衡信息流通与隐私保护之间的关系, 保障数据要素安全有序流动, 已成为当前亟待解决的问题. 然而, 现有访问控制技术在领域数据共享场景研究中仍存在与信任评估融合不足、动态调整能力欠缺以及难以精准授权等问题. 针对上述问题, 提出一个基于博弈论的可信动态访问控制模型方案, 该方案融合“可信评估-动态调整-访问决策”三层协同机制. 首先, 基于属性权重算法, 设计多因素可信预测模型, 计算访问主体的信任概率; 其次, 从长期稳定角度出发, 构建访问主体与客体之间的演化博弈动态调整模型, 周期性地动态调整奖惩激励机制与访问授权阈值, 实现访问控制的适应性优化; 最后, 基于贝叶斯博弈论建立不完全信息实时决策模型, 依据混合策略纳什均衡做出访问控制决策, 并通过均衡状态反馈更新信任度. 仿真实验和敏感性分析的结果表明, 该方案能够有效提高访问控制的准确性, 实现访问控制策略动态调整和精准授权.

    Abstract:

    Access control technology is a security mechanism for managing users’ access to resources, which can effectively prevent unauthorized access and resource leakage. In the digital age, how to balance the relationship between information circulation and privacy protection via effective access control technology and ensure the safe and orderly flow of data elements has become a problem to be urgently addressed at present. However, the existing access control technology still has problems such as insufficient integration with trust evaluation, lack of dynamic adjustment capabilities, and difficulty in precise authorization in the research on domain data sharing scenarios. To this end, a trustworthy dynamic access control model scheme based on game theory is proposed, which integrates a three-layer collaborative mechanism of “trustworthy evaluation, dynamic adjustment, and access decision”. Firstly, based on the attribute weight algorithm, a multi-factor trustworthy prediction model is designed to calculate the trust probability of the access subject. Secondly, from the perspective of long-term stability, an evolutionary game dynamic adjustment model between the access subject and the object is built to periodically and dynamically adjust the reward and punishment incentive mechanism and access authorization threshold, thereby achieving the adaptive optimization of access control. Finally, based on Bayesian game theory, an incomplete information real-time decision-making model is built, and access control decisions are made based on the mixed strategy Nash equilibrium, with the trust degree updated by the equilibrium state feedback. The results of simulation experiments and sensitivity analysis verify that the proposed scheme can effectively improve the access control accuracy and achieve dynamic adjustment of access control strategies and accurate authorization.

    参考文献
    相似文献
    引证文献
引用本文

周由胜,鞠祯,左祥建,刘媛妮.基于博弈论的可信动态访问控制方案.软件学报,,():1-28

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2025-05-08
  • 最后修改日期:2025-09-23
  • 录用日期:
  • 在线发布日期: 2026-04-29
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62562563 传真:010-62562533 Email:jos@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号