WO2017181775A1 - 分布式授权管理方法及装置 - Google Patents
分布式授权管理方法及装置 Download PDFInfo
- Publication number
- WO2017181775A1 WO2017181775A1 PCT/CN2017/075429 CN2017075429W WO2017181775A1 WO 2017181775 A1 WO2017181775 A1 WO 2017181775A1 CN 2017075429 W CN2017075429 W CN 2017075429W WO 2017181775 A1 WO2017181775 A1 WO 2017181775A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- resource
- attribute
- address
- access control
- pdp
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/102—Entity profiles
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
Definitions
- the present application relates to the field of communications technologies, and in particular, to a distributed authorization management method and apparatus.
- OneM2M the Internet of Things standardization organization, is committed to developing a series of technical specifications for constructing a common M2M (Machine-To-Machine) service layer.
- the core of oneM2M is data sharing, which is realized by the sharing of data items on the resource tree defined in oneM2M CSE (Common Services Entity).
- OneM2M implements sharing and interaction of service layer resources by operating on a standardized resource tree.
- the oneM2M resource tree exists in the CSE defined by the oneM2M system.
- the form of the oneM2M resource tree is shown in Figure 1 according to the definition in the oneM2M functional architecture specification (oneM2M TS-0001: "Functional Architecture"). Operations such as Create, Retrieve, Update, and Delete can be performed on oneM2M resources.
- the authorization-related resource in the resource defined by oneM2M is the access control policy resource ⁇ accessControlPolicy>, which defines an Access Control Policy (ACP).
- ACP Access Control Policy
- the ⁇ accessControlPolicy> resource is uniquely identified by the resource ID, and other resources specify the applicable access control policy through the accessControlPolicyIDs attribute.
- the security specification (oneM2M TS-0003: "Security Solutions”) in the oneM2M series specification gives a high-level description of the oneM2M authorization architecture.
- the main components and basic processes of the authorization architecture are given, but not at the resource structure level.
- the embodiment of the present application provides a distributed authorization management method and apparatus, and a distributed authorization management scheme is provided at a resource structure level.
- the PEP obtains a resource according to the received resource access request, and the resource includes an attribute for carrying the address of the authorized entity.
- the PEP obtains an authorized entity address according to an attribute of the resource for carrying an authorized entity address, where the authorized entity includes one or more of a PDP, a PRP, and a PIP;
- the PEP performs an access control decision for the resource access request according to the acquired information for performing an access control decision.
- the resource that includes the attribute for carrying the address of the authorized entity is an access control policy resource that includes an attribute for carrying the address of the authorized entity;
- the PEP obtains a PDP address according to the attribute of the resource used to carry the address of the authorized entity, including:
- the PEP does not obtain an access control policy from the access control policy resource that includes the attribute for carrying the authorized entity address, obtain the PDP address according to the attribute in the resource for carrying the authorized entity address.
- the PEP obtains the resource according to the received resource access request, and the resource includes an attribute for carrying the address of the authorized entity, including:
- the PEP does not obtain an access control policy from the access control policy resource, acquiring the resource that includes an attribute for carrying an authorized entity address.
- the attribute for carrying an authorization entity address includes: a PDP access point attribute, where the PDP access point attribute is used to carry one or more PDP addresses.
- the PEP obtains a PDP address according to the attribute of the resource for carrying the authorized entity address, and the PEP is connected according to the PDP in the resource.
- the in point attribute acquires the PDP address and selects a PDP address from the obtained PDP addresses.
- the PDP acquires a resource according to the received access control decision request, and the resource includes an attribute for carrying the address of the authorized entity;
- the PDP obtains a PRP address according to an attribute of the resource used to carry an authorized entity address
- the PDP obtains an access control policy from the PRP corresponding to the PRP address according to the obtained PRP address;
- the PDP performs an access control decision according to the obtained access control policy.
- the resource that includes the attribute for carrying the address of the authorized entity is an access control policy resource that includes an attribute for carrying the address of the authorized entity;
- the PDP obtains a PRP address according to an attribute of the resource for carrying an authorized entity address, including:
- the PDP does not obtain the access control policy from the access control policy resource that includes the attribute for carrying the authorized entity address, obtain the PRP address according to the attribute in the resource for carrying the authorized entity address.
- the PDP acquires a resource according to the received access control decision request, and the resource includes an attribute for carrying an address of the authorized entity, including:
- the PEP does not obtain an access control policy from the access control policy resource, acquiring the resource that includes an attribute for carrying an authorized entity address.
- the attribute for carrying the address of the authorized entity includes: a PRP access point attribute, where the PRP access point attribute is used to carry one or more PRP addresses.
- the PDP obtains a PRP address according to the attribute of the resource used to carry the authorized entity address, and the PDP is connected according to the PRP in the resource.
- the inbound attribute obtains multiple PRP addresses and selects a PRP address from the obtained PRP addresses.
- the PDP acquires a resource according to the received access control decision request, and the resource includes an attribute for carrying the address of the authorized entity;
- the PDP obtains a PIP address according to an attribute in the resource for carrying an address of an authorized entity
- the PDP acquires access control information from the corresponding PIP according to the obtained PIP address
- the PDP performs an access control decision according to the acquired access control information.
- the PDP acquires a resource according to the received access control decision request, and the resource includes an attribute for carrying the address of the authorized entity, where the PDP does not locally locate the PDP according to the received access control decision request.
- the resource of the target resource for which the requested access is applied includes the attribute for carrying the attribute of the authorized entity address.
- the attribute for carrying an authorized entity address includes: a PIP access point attribute, where the PIP access point attribute is used to carry one or more PIP addresses.
- the PDP obtains a PIP address according to the attribute of the resource used to carry the authorized entity address, including: the PDP is connected according to the PIP in the resource.
- the in point attribute obtains the PIP address and selects a PIP address from the obtained PIP addresses.
- a first acquiring module configured to acquire a resource according to the received resource access request, where the resource includes an attribute for carrying an address of the authorized entity
- a second obtaining module configured to obtain an authorized entity address according to an attribute of the resource for carrying an authorized entity address, where the authorized entity includes one or more of a PDP, a PRP, and a PIP;
- a third obtaining module configured to obtain, according to the obtained authorized entity address, information for performing an access control decision from an authorized entity corresponding to the authorized entity address;
- the decision execution module is configured to perform an access control decision for the resource access request according to the obtained information for performing an access control decision.
- the resource that includes the attribute for carrying the address of the authorized entity is an access control policy resource that includes an attribute for carrying the address of the authorized entity;
- the second obtaining module is specifically configured to: if not included from the included Obtaining an access control policy in an access control policy resource that carries an attribute of an authorized entity address, and acquiring a PDP address according to an attribute of the resource for carrying an authorized entity address; or
- the first acquiring module is configured to: obtain an access control policy resource applicable to the target resource that is requested to be accessed according to the received resource access request, and obtain the used control policy if the access control policy is not obtained from the resource.
- the attribute for carrying an authorization entity address includes: a PDP access point attribute, where the PDP access point attribute is used to carry one or more PDP addresses.
- a first acquiring module configured to acquire a resource according to the received access control decision request, where the resource includes an attribute for carrying an address of the authorized entity
- a second acquiring module configured to acquire a PRP address according to an attribute used to carry an authorized entity address in the resource
- the third obtaining module is configured to obtain an access control policy from the PRP corresponding to the PRP address according to the obtained PRP address;
- the decision module is configured to perform an access control decision according to the obtained access control policy.
- the resource that includes the attribute for carrying the address of the authorized entity is an access control policy resource that includes an attribute for carrying the address of the authorized entity;
- the second obtaining module is specifically configured to: if not included from the included Obtaining an access control policy in an access control policy resource that carries an attribute of an authorized entity address, and acquiring a PRP address according to an attribute of the resource for carrying an authorized entity address; or
- the first obtaining module is configured to: obtain an access control policy resource applicable to the target resource that is requested to be accessed according to the received access control decision request, and obtain the access control policy if the access control policy is not obtained from the resource There are resources for hosting attributes of authorized entity addresses.
- the attribute for carrying the address of the authorized entity includes: a PRP access point attribute, where the PRP access point attribute is used to carry one or more PRP addresses.
- a first acquiring module configured to acquire a resource according to the received access control decision request, where the resource includes an attribute for carrying an address of the authorized entity
- a second acquiring module configured to acquire a PIP address according to an attribute used to carry an authorized entity address in the first resource
- the third obtaining module is configured to obtain access control information from the corresponding PIP according to the obtained PIP address;
- the decision module is configured to perform an access control decision according to the obtained access control information.
- the first obtaining module is specifically configured to: according to the received access control decision request, the required access control information is not obtained locally in the PDP, and the target resource for obtaining the requested access is used for inclusion A resource that carries an attribute that authorizes an entity address.
- the attribute for carrying an authorized entity address includes: a PIP access point attribute, where the PIP access point attribute is used to carry one or more PIP addresses.
- the authorization entity acquires an address of another authorized entity according to an attribute for carrying an authorization entity address in a resource that includes an attribute for carrying an authorization entity address, so as to obtain corresponding information from other authorized entities based on the address,
- a distributed authorization management scheme is given at the resource structure level.
- FIG. 1 is a schematic diagram of a oneM2M resource tree in the prior art
- FIG. 2 is a schematic diagram of a oneM2M authorization architecture in the prior art
- FIG. 3 is a schematic structural diagram of an ⁇ accessControlPolicy> resource defined in an embodiment of the present application.
- FIG. 4 and FIG. 5 are schematic diagrams of interaction processes between a PEP and a PDP implemented based on a PDP-PoAs attribute according to an embodiment of the present disclosure
- FIG. 6 and FIG. 7 are schematic diagrams of the interaction process between a PDP and a PRP implemented by using a PRP-PoAs attribute according to an embodiment of the present disclosure
- FIG. 8 and FIG. 9 are schematic diagrams of interaction between a PDP and a PIP implemented based on a PIP-PoAs attribute according to an embodiment of the present disclosure
- FIG. 10 is a schematic diagram of a specific application scenario provided by an embodiment of the present application.
- FIG. 11 is a schematic structural diagram of a PEP according to an embodiment of the present disclosure.
- FIG. 12 is a schematic structural diagram of a PDP according to an embodiment of the present disclosure.
- FIG. 13 is a second schematic structural diagram of a PDP according to an embodiment of the present application.
- oneM2M defines two basic entities: Application Entity (AE) and Common Service Entity (CSE).
- AE Application Entity
- CSE Common Service Entity
- the AE is located at the application layer and implements an M2M application logic.
- An application logic can reside in multiple M2M nodes or multiple execution instances in a single node.
- Each execution instance of the application logic is called a AE, each AE is identified by a unique AE-ID.
- the CSE consists of "common service functions" in a set of M2M environments. Each CSE is identified by a unique CSE-ID. The oneM2M resource tree exists in the CSE.
- oneM2M defines three types of resources:
- Normal Resource Has a specific resource structure and resource attributes.
- Virtual Resource Does not have a specific resource structure and resource attributes, and is mainly used to trigger a specific process.
- Announced Resource It has a specific resource structure and attributes. This resource is a copy of some content of common resources on other entities. The main purpose is to facilitate resource discovery.
- the authorization architecture given in the oneM2M Security Solution Technical Specification (oneM2M TS-0003: Security Solutions) is shown in Figure 2.
- the architecture can include the following components:
- the PEP coexists with the application system that needs access control, and is called by the application system.
- the PEP generates an access control decision request according to the resource access request of the resource access initiator and sends it to the PDP. Then, based on the access control decision response returned by the PDP, it is determined whether to execute the resource access request.
- the PDP is responsible for determining whether to agree to the target resource requested by the access control decision request sent by the PEP according to the access control policy, and returning the decision result to the access control decision response. PEP.
- the PRP requests the applicable access control policy according to the access control policy provided by the PDP, and returns the obtained access control policy to the PDP.
- PIP Policy Information Point
- the oneM2M basic resource access control process can include:
- the resource access initiation direction PEP sends a resource access request (Access Request), and the PEP sends an access control decision request (Decision Request) to the PDP according to the resource access request.
- Access Request resource access request
- Decision Request access control decision request
- the PDP sends an access control policy request (Policy Request) to the PRP according to the access control decision request sent by the PEP, and the PRP returns an access control policy response (Policy Response) to the PDP, where the access control policy response includes an access control policy.
- Policy Request an access control policy request
- Policy Response an access control policy response
- the PDP analyzes and judges the content included in the access control decision request and the access control policy. If other attributes are required for analysis and decision, the PDP sends an access control information request (Attribute Request) to the PIP, and the PIP sends an access control to the PDP.
- the information response includes the access control related information acquired according to the access control information request.
- the PDP sends an access control decision response (Decision Response) to the PEP, where the control decision response includes an access control decision result.
- the PEP determines whether to perform the resource access request of the resource access initiator according to the access control decision result in the access control decision response.
- the ⁇ accessControlPolicy> resource type defined in oneM2M is redefined in the embodiment of the present application, so that it can provide the distributed authorization system with the address information of the authorized entity.
- the newly defined ⁇ accessControlPolicy> resource can also determine which authorization or related entities should send corresponding authorizations according to the newly defined ⁇ accessControlPolicy> resource in the case of distributed authorization.
- the request that is, the address information about the PDP, PRP or PIP is provided to the access control system.
- FIG. 3 The basic structure of the redefined ⁇ accessControlPolicy> resource is shown in Figure 3.
- "0..n” is used to indicate the possible number of attributes or sub-resources, n is an integer greater than or equal to 1; and "L” is used to indicate that the attribute value may be in the form of a list.
- PDP access point attribute used to carry a set of (ie, one or more) addresses of entities that can implement PDP functions; attribute names of the attributes can be represented as PDP-PoAs or pdpAddresses, attribute values; The address of the entity that can implement the PDP function, such as a PDP address list; the PDP-PoAs attribute is an optional attribute.
- PoA is an abbreviation of Point of Access, meaning an access point;
- PRP access point attribute used to carry a set of (ie, one or more) addresses of entities that can implement PRP function; the attribute name of the attribute can be represented as PRP-PoAs or prpAddresses, and the attribute value is a set of PRP functions.
- the address of the entity such as a list of PRP addresses; the PRP-PoAs attribute is an optional attribute;
- PIP access point attribute used to carry a set of (ie, one or more) addresses of entities that can implement PIP functions; the attribute name of the attribute can be expressed as PIP-PoAs or pipAddresses, and the attribute value is a set of PIP functions.
- the address of the entity such as a list of PIP addresses; the PIP-PoAs attribute is an optional attribute.
- ⁇ accessControlPolicy> resource may also include one or more of the following defined attributes:
- Privileges attribute used to carry access control policies
- the above privileges attribute can be adjusted from the original "required” to "optional”. Further, if the ⁇ accessControlPolicy> resource contains the privileges attribute, the number can be one or more.
- the ⁇ accessControlPolicy> resource may also include a sub-resource, expressed as ⁇ subscription>.
- the number of ⁇ subscription> resources contained in the ⁇ accessControlPolicy> resource can be one or more.
- ⁇ subscription> can be a child resource defined by oneM2M.
- the newly added resource attribute is used to carry the address of the authorized entity, and then the distributed authorization management can be implemented according to the ⁇ accessControlPolicy> resource.
- the ⁇ accessControlPolicy> resource defined in the prior art may be kept unchanged, and the foregoing three resource attributes (such as PDP-PoAs attribute, PRP-PoAs attribute, and PIP-PoAs attribute) may be maintained.
- One or more organizations are in a separately defined new resource, for example, the newly defined resource can be named ⁇ authorizationEntity>.
- ⁇ authorizationEntity> resource Similar to the ⁇ accessControlPolicy> resource processing method, for a resource that cannot directly have the ⁇ authorizationEntity> sub-resource type, it can be associated with an ⁇ authorizationEntity> resource through the common attribute ⁇ authorizationEntityID>.
- the resource attributes in the ⁇ authorizationEntity> resource are used in the same way as in the ⁇ accessControlPolicy> resource type.
- the priority order of the ⁇ accessControlPolicy> resource defined in the prior art and the ⁇ authorizationEntity> resource defined in the embodiment of the present application may be: the priority of the ⁇ accessControlPolicy> resource is higher than the priority of the ⁇ authorizationEntity> resource. .
- the distributed authorization management process provided by the embodiment of the present application is described below by taking the redefined ⁇ accessControlPolicy> resource as an example.
- the above principles and processing methods are also applicable to the process of implementing distributed authorization management according to the newly defined ⁇ authorizationEntity> resource.
- a process for implementing an interaction between a PEP and a PDP based on a newly defined attribute for carrying an authorized entity address may include the following steps:
- Step 401 The PEP acquires a resource according to the received resource access request, where the resource includes an attribute for carrying the address of the authorized entity (hereinafter, the description is convenient to refer to the resource as the first resource).
- Step 402 The PEP obtains an authorized entity address according to an attribute used to carry an authorized entity address in the first resource.
- the authorized entity includes one or more of a PDP, a PRP, and a PIP.
- the PEP obtains a PDP address according to the PDP-PoAs attribute in the first resource, obtains a PRP address according to the PRP-PoAs attribute in the first resource, and obtains a PIP address according to the PIP-PoAs attribute in the first resource.
- Step 403 The PEP obtains information for performing an access control decision from an authorized entity corresponding to the authorized entity address according to the obtained authorized entity address.
- the PEP sends an access control decision request to the corresponding PDP according to the obtained PDP address; after receiving the access control decision request, the PDP uses the corresponding access control policy to perform access control decision according to the target resource, and access control
- the decision information ie, the decision result
- the PEP uses the corresponding access control policy to perform access control decision according to the target resource, and access control
- the decision information ie, the decision result
- the PEP may send an access control policy request to the corresponding PRP according to the obtained PRP address. After receiving the access control policy request, the PRP obtains the access control policy, and the access control policy is carried in the access control policy response and sent to the PEP. .
- the PEP may send an access control information request to the corresponding PIP according to the obtained PIP address. After receiving the access control information request, the PIP obtains the access control information, and the access control information is carried in the access control information response and sent to the PEP. .
- Step 404 The PEP performs the resource access request according to the obtained information for performing an access control decision. Perform access control decisions.
- the first resource in the above process is the above-mentioned redefined ⁇ accessControlPolicy> resource.
- the PEP obtains the ⁇ accessControlPolicy> resource applicable to the target resource that is requested to be accessed according to the received resource access request.
- the PEP obtains the value of the privileges attribute of the ⁇ accessControlPolicy> resource, and the attribute value is the access control policy.
- the PEP does not obtain an access control policy from the ⁇ accessControlPolicy> resource (for example, if the ⁇ accessControlPolicy> resource does not contain the privileges attribute, or if the ⁇ accessControlPolicy> resource contains the privileges attribute but the value of the attribute is empty If the PEP cannot obtain the access control policy from the ⁇ accessControlPolicy> resource, the PDP address is obtained according to the PDP-PoAs attribute in the ⁇ accessControlPolicy> resource.
- the first resource in the foregoing process is the above-mentioned redefined ⁇ authorizationEntity> resource
- the second resource is a ⁇ accessControlPolicy> resource in the prior art.
- the PEP obtains the ⁇ accessControlPolicy> resource applicable to the target resource that is requested to be accessed according to the received resource access request, and the PEP obtains the value of the privileges attribute of the ⁇ accessControlPolicy> resource, where the attribute value is the access control policy, if the PEP is not Obtain an access control policy from the ⁇ accessControlPolicy> resource (for example, if the ⁇ accessControlPolicy> resource does not contain the privileges attribute, or if the ⁇ accessControlPolicy> resource contains the privileges attribute but the value of the attribute is empty, the PEP cannot Obtain an access control policy from the ⁇ accessControlPolicy> resource to get the ⁇ authorizationEntity> resource.
- the ⁇ authorizationEntity> resource may include the above PDP-PoAs attribute,
- the following takes a new implementation of the ⁇ accessControlPolicy> resource as an example, and describes a specific implementation process of FIG. 4 in conjunction with FIG. 5. As shown in FIG. 5, the process may include the following steps:
- Step 501 After the PEP in the Hosting CSE intercepts the resource access request from the resource access initiator (originator), the PSP in the host CSE retrieves the ⁇ accessControlPolicy> resource applicable to the target resource according to the requirements of the oneM2M system.
- Step 502 The PEP checks whether the ⁇ accessControlPolicy> resource contains the privileges attribute and the attribute value is not empty. If the privileges attribute is not included or the attribute value is null, then go to step 503; if the privileges attribute is included and the attribute value is not empty, then go to step 506;
- Step 503 The PEP checks whether the ⁇ accessControlPolicy> resource contains the PDP-PoAs attribute and the attribute value is not empty. If the PDP-PoAs attribute is included and the attribute value is not empty, then go to step 504; if the PDP-PoAs attribute is not included or the attribute value is empty, go to step 507;
- Step 504 The PEP reads the PDP address list in the PDP-PoAs attribute, and obtains a PDP address (ie, PoA), and then proceeds to step 505;
- Step 505 The PEP generates an Access Control Decision Request and sends it to the PDP corresponding to the PDP address, and receives the returned access control decision response (Access Control) from the PDP. Decision Response), the access control decision response includes access control decision information, and then proceeds to step 508;
- Step 506 The PEP reads the access control policy in the privileges attribute, and uses it to evaluate the resource access request of the initiator, thereby obtaining an access control decision, and then proceeds to step 508;
- Step 507 the PEP performs error processing, and then proceeds to step 508;
- Step 508 The PEP performs an access control decision and ends the access control process. If it is from step 507 to step 508, since error processing is performed in step 507, in step 508, the PEP may reject the resource access request of the resource access originator (originator), or proceed according to a predetermined agreement. deal with.
- a process for implementing interaction between a PDP and a PRP based on a newly defined PRP access point attribute (hereinafter referred to as a PRP-PoAs attribute) according to an embodiment of the present disclosure, as shown in the figure, the process may include the following step:
- Step 601 The PDP acquires a resource according to the received access control decision request, where the resource includes an attribute for carrying the address of the authorized entity (hereinafter, the description is convenient to refer to the resource as the first resource);
- Step 602 The PDP obtains a PRP address according to an attribute used to carry an authorized entity address in the first resource. Specifically, the PEP obtains a PRP address according to the PRP-PoAs attribute in the first resource.
- Step 603 The PDP obtains an access control policy from the PRP corresponding to the PRP address according to the obtained PRP address.
- the PDP sends an access control policy request to the corresponding PRP according to the obtained PRP address.
- the PRP obtains the access control policy, and carries the access control policy in the access control policy response. Give the PDP.
- Step 604 The PDP performs an access control decision according to the obtained access control policy.
- the first resource in the above process is the above-mentioned redefined ⁇ accessControlPolicy> resource.
- the PDP obtains the ⁇ accessControlPolicy> resource applicable to the target resource that is requested to be accessed according to the received access control policy request.
- the PDP obtains the value of the privileges attribute of the ⁇ accessControlPolicy> resource, and the attribute value is the access control.
- the PDP if the PDP does not obtain an access control policy from the ⁇ accessControlPolicy> resource (for example, if the ⁇ accessControlPolicy> resource does not contain the privileges attribute, or if the ⁇ accessControlPolicy> resource contains the privileges attribute but the value of the attribute is empty If the PDP cannot obtain the access control policy from the ⁇ accessControlPolicy> resource, the PRP address is obtained based on the PRP-PoAs attribute in the ⁇ accessControlPolicy> resource.
- the first resource in the foregoing process is the above-mentioned redefined ⁇ authorizationEntity> resource
- the second resource is a ⁇ accessControlPolicy> resource in the prior art.
- the PDP obtains the ⁇ accessControlPolicy> resource applicable to the target resource that is requested to be accessed according to the received access control policy request, and the PDP obtains the value of the privileges attribute of the ⁇ accessControlPolicy> resource, where the attribute value is the access control policy, if the PDP The access control policy is not obtained from the ⁇ accessControlPolicy> resource (for example, if the privileges attribute is not included in the ⁇ accessControlPolicy> resource, or the privileges attribute is included in the ⁇ accessControlPolicy> resource, but If the value of the attribute is empty, the PDP cannot obtain the access control policy from the ⁇ accessControlPolicy> resource, and the ⁇ authorizationEntity> resource is obtained.
- the ⁇ authorizationEntity> resource may include the above PDP-PoA
- the following takes a new implementation of the ⁇ accessControlPolicy> resource as an example, and describes a specific implementation process of FIG. 6 in conjunction with FIG. 7. As shown in FIG. 7, the process may include the following steps:
- Step 701 After receiving the access control decision request from the PEP, the PDP retrieves the applicable ⁇ accessControlPolicy> resource by using the target resource address in the access control decision request.
- Step 702 The PDP checks whether the ⁇ accessControlPolicy> resource contains the privileges attribute and the attribute value is not empty. If the privileges attribute is not included or the attribute value is null, then go to step 703; if the privileges attribute is included and the attribute value is not empty, then go to step 706;
- Step 703 The PDP checks whether the ⁇ accessControlPolicy> resource contains the PRP-PoAs attribute and the attribute value is not empty. If the PRP-PoAs attribute is included and the attribute value is not empty, proceed to step 704; if the PRP-PoAs attribute is not included or the attribute value is null, proceed to step 707;
- Step 704 The PDP reads the PRP address list in the PRP-PoAs attribute, and obtains a PRP address, and then proceeds to step 705;
- Step 705 The PDP generates an Access Control Policy Request and sends it to the PRP corresponding to the PRP address, and receives the returned Access Control Policy Response (Access Control Policy Response) from the PRP to obtain the access in the response. Control the policy, then proceeds to step 708;
- Step 706 The PDP reads the access control policy in the privileges attribute, and then proceeds to step 708;
- Step 707 The PDP performs error processing, and then proceeds to step 708;
- Step 708 The PDP ends the process of acquiring the access control policy. Further, the PDP can make an access control decision according to the obtained access control policy.
- a process for implementing interaction between a PDP and a PIP based on a newly defined PIP access point attribute (hereinafter referred to as a PIP-PoAs attribute) according to an embodiment of the present application, as shown in the figure, the process may include the following step:
- Step 801 The PDP acquires a resource according to the received access control decision request, where the resource includes an attribute for carrying the address of the authorized entity (hereinafter, the description is convenient to refer to the resource as the first resource);
- Step 802 The PDP obtains a PIP address according to an attribute used to carry an authorized entity address in the first resource. Specifically, the PEP obtains a PIP address according to the PIP-PoAs attribute in the first resource.
- Step 803 The PDP acquires access control information from the corresponding PIP according to the obtained PIP address.
- the PDP sends an access control information request to the corresponding PIP according to the obtained PIP address; after receiving the access control information request, the PIP obtains the access control information, and carries the access control information in the access control information response. Give the PDP.
- Step 804 The PDP performs an access control decision according to the obtained access control information.
- the first resource in the above process is the above-mentioned redefined ⁇ accessControlPolicy> resource.
- the PDP obtains the required access control information locally from the PDP according to the received access control policy request, and acquires an ⁇ accessControlPolicy> resource applicable to the target resource that is requested to be accessed.
- the first resource in the foregoing process is the above-mentioned redefined ⁇ authorizationEntity> resource
- the second resource is a ⁇ accessControlPolicy> resource in the prior art.
- the PDP obtains the required authorization control information from the PDP according to the received access control policy request, and acquires an ⁇ authorizationEntity> resource applicable to the target resource that is requested to be accessed.
- the ⁇ authorizationEntity> resource may include the above PDP-PoAs attribute, PRP-PoAs attribute, and PIP-PoAs attribute, all of which are optional attributes.
- FIG. 9 The specific implementation process of FIG. 8 is described below with reference to FIG. 9 taking the newly defined ⁇ accessControlPolicy> resource as an example. As shown in FIG. 9, the process may include the following steps:
- Step 901 After receiving the access control decision request from the PEP, the PDP checks the parameters in the access control decision request to determine whether there is local access control information, such as a role identifier or a token identifier. If yes, go to step 902; otherwise, go to step 907;
- local access control information such as a role identifier or a token identifier.
- Step 902 The PDP retrieves the applicable ⁇ accessControlPolicy> resource by using the target resource address in the access control decision request.
- Step 903 The PDP checks whether the ⁇ accessControlPolicy> resource contains the PIP-PoAs attribute and the attribute value is not empty. If the PIP-PoAs attribute is included and the attribute value is not empty, then go to step 904; if the PIP-PoAs attribute is not included or the attribute value is empty, then go to step 906;
- Step 904 The PDP reads the PIP address list in the PIP-PoAs attribute, and obtains a PIP address, and then proceeds to step 905;
- Step 905 The PDP generates an access control information request (Access Control Information Request), and sends the access control information request to the PIP, and receives the returned access control information response (Access Control Information Response) from the PIP, and obtains the access control information in the response. And then proceeds to step 907;
- Step 906 The PDP performs error processing, and then proceeds to step 907;
- Step 907 The PDP ends the process of acquiring the access control information. Further, the PDP may perform an access control decision according to the acquired access control information.
- the oneM2M Application Service Provider reads the IoT device installed in the user's home through the oneM2M platform provided by the oneM2M Service Provider.
- CSE0 is the infrastructure node of oneM2M service provider
- CSE1 is the user's home gateway
- CSE2, CSE3 and CSE4 are the Internet of Things devices in the user's home
- AE1 is the application service entity registered by oneM2M application service provider to CSE0
- CSE3 and CSE4 access control policies Both the access control decision points are set in CSE1; AE1 accesses the resources in CSE2, CSE3, and CSE4 through roles.
- the privileges attribute in the access control policy resource ( ⁇ accessControlPolicy> resource) in CSE2, CSE3, and CSE4 is empty, but the PDP-PoAs attribute is set to point to CSE1 (that is, the attribute value of the PDP-PoAs attribute contains the address of CSE1);
- the PIP-PoAs attribute in the access control policy resource ( ⁇ accessControlPolicy> resource) in CSE1 is set to point to CSE0 (that is, the address of the attribute of the PDP-PoAs attribute containing CSE0);
- the role information of AE1 is stored in CSE0.
- the process of distributed authorization access control may include:
- AE1 sends a data read command to the CSE2 resource tree, which includes a role identifier
- CSE2 checks the local access control policy and finds that the privacy attribute of the access control resource associated with the resource is empty, but the PDP-PoAs is not empty and points to CSE1, so an access control decision request is generated and sent to CSE1;
- CSE1 checks the access control policy resources stored locally for the target resource and obtains an access control policy
- CSE1 checks the access control decision request sent by CSE2 and finds that it contains the role identifier. It checks the access control policy resource stored in the local target resource and finds that PIP-PoAs is not empty and points to CSE0, thus generating an access control information. Request and send to CSE0;
- CSE0 retrieves relevant role information according to the access control information request of CSE1, and returns it to CSE1 through the access control information response;
- CSE1 evaluates the resource access request of AE1 according to the access control policy and the role information of AE1, and returns the access control decision to CSE2 through the access control decision response;
- CSE2 decides whether to perform the resource access request of AE1 according to the access control decision.
- the authorization entity obtains the address of the other authorized entity according to the attribute used to carry the authorized entity address in the resource defined in the resource defined in the embodiment of the present application, which is used to carry the authorized entity address, thereby
- the address obtains corresponding information from other authorized entities, and a distributed authorization management scheme is given at the resource structure level.
- the embodiment of the present application further provides a PEP.
- FIG. 11 is a schematic structural diagram of a PEP according to an embodiment of the present disclosure.
- the PEP can implement the related process provided by the foregoing embodiment of the present application.
- the PEP may include: a first obtaining module 1101, a second obtaining module 1102, a third obtaining module 1103, and a decision executing module 1104, where:
- the first obtaining module 1101 is configured to acquire a resource according to the received resource access request, where the resource includes an attribute for carrying an address of the authorized entity;
- the second obtaining module 1102 is configured to obtain an authorized entity address according to an attribute used to carry an authorized entity address in the resource, where the authorized entity includes one or more of a PDP, a PRP, and a PIP;
- the third obtaining module 1103 is configured to obtain, according to the obtained authorized entity address, information for performing an access control decision from an authorized entity corresponding to the authorized entity address;
- the decision execution module 1104 is configured to perform an access control decision for the resource access request according to the acquired information for performing an access control decision.
- the resource that includes the attribute for carrying the address of the authorized entity is an access control policy resource that includes an attribute for carrying the address of the authorized entity; the second obtaining module 1102 may be specifically configured to: If the access control policy is not obtained from the access control policy resource that includes the attribute for carrying the authorized entity address, the PDP address is obtained according to the attribute of the resource for carrying the authorized entity address.
- the first obtaining module 1101 may be configured to: obtain, according to the received resource access request, an access control policy resource applicable to the target resource that is requested to be accessed; if not obtained from the resource The access control policy acquires the resource containing the attribute for carrying the address of the authorized entity.
- the attribute for carrying an authorization entity address includes: a PDP access point attribute, where the PDP access point attribute is used to carry one or more PDP addresses.
- the embodiment of the present application further provides a PDP.
- FIG. 12 is a schematic structural diagram of a PDP provided by an embodiment of the present application.
- the PDP can implement the related process provided by the foregoing embodiment of the present application.
- the PDP may include: a first obtaining module 1201, a second obtaining module 1202, a third obtaining module 1203, and a decision module 1204, wherein:
- the first obtaining module 1201 is configured to acquire a resource according to the received access control decision request, where the resource includes an attribute for carrying an address of the authorized entity;
- the second obtaining module 1202 is configured to obtain a PRP address according to an attribute used to carry an authorized entity address in the resource.
- the third obtaining module 1203 is configured to obtain an access control policy from the PRP corresponding to the PRP address according to the obtained PRP address.
- the decision module 1204 is configured to perform an access control decision according to the obtained access control policy.
- the resource that includes the attribute for carrying the address of the authorized entity is an access control policy resource that includes an attribute for carrying the address of the authorized entity.
- the second obtaining module 1202 is specifically configured to: And obtaining an access control policy from the access control policy resource that includes the attribute for carrying the address of the authorized entity, and acquiring the PRP address according to the attribute in the resource for carrying the address of the authorized entity.
- the first obtaining module 1201 is specifically configured to: obtain, according to the received access control decision request, an access control policy resource applicable to the target resource that is requested to be accessed; if the PEP is not from the resource When the access control policy is obtained, the resource containing the attribute for carrying the address of the authorized entity is obtained.
- the attribute for carrying the address of the authorized entity includes: a PRP access point attribute, where the PRP access point attribute is used to carry one or more PRP addresses.
- the embodiment of the present application further provides a PDP.
- FIG. 13 is a schematic structural diagram of a PDP according to an embodiment of the present disclosure.
- the PDP can implement the related process provided by the foregoing embodiment of the present application.
- the PDP may include: a first obtaining module 1301, a second obtaining module 1302, a third obtaining module 1303, and a decision module 1304, where:
- the first obtaining module 1301 is configured to acquire a resource according to the received access control decision request, where the resource includes an attribute for carrying an address of the authorized entity;
- the second obtaining module 1302 is configured to obtain a policy information point PIP address according to an attribute used to carry an authorized entity address in the resource.
- the third obtaining module 1303 is configured to obtain access control information from the corresponding PIP according to the obtained PIP address;
- the decision module 1304 is configured to perform an access control decision according to the obtained access control information.
- the first obtaining module 1301 is specifically configured to: according to the received access control decision request, the required access control information is not obtained locally in the PDP, and the target resource for obtaining the requested access is included for carrying A resource that authorizes the attributes of an entity address.
- the attribute for carrying an authorized entity address includes: a PIP access point attribute, where the PIP access point attribute is used to carry one or more PIP addresses.
- Any of the above modules in the embodiments of the present application may be implemented by a processor or a physical module such as a processor having a transceiving function.
- oneM2M only defines the high-level architecture of the authorization system, and does not provide a specific solution.
- the embodiment of the present application provides a solution for implementing distributed authorization system management in a oneM2M system.
- the embodiment of the present application adds the required function by redefining the oneM2M ⁇ accessControlPolicy> resource type, thereby avoiding the new resource type and a large number of modifications to the TS.
- the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer readable memory include instructions.
- the instruction means implements the functions specified in a block or blocks of a flow or a flow and/or a block diagram of the flowchart.
- These computer program instructions can also be loaded onto a computer or other programmable data processing device such that a series of operational steps are performed on a computer or other programmable device to produce computer-implemented processing for execution on a computer or other programmable device.
- the instructions provide steps for implementing the functions specified in one or more of the flow or in a block or blocks of a flow diagram.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Storage Device Security (AREA)
Abstract
本申请公开了分布式授权管理方法及装置。本申请中,授权实体根据包含有用于承载授权实体地址的属性的资源中用于承载授权实体地址的属性获取其他授权实体的地址,从而基于该地址从其他授权实体获取相应信息,在资源结构层面给出了分布式授权管理方案。
Description
本申请要求在2016年4月18日提交中国专利局、申请号为201610242998.5、发明名称为“分布式授权管理方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本申请涉及通信技术领域,尤其涉及分布式授权管理方法及装置。
物联网标准化组织oneM2M致力于开发一系列用于构造公共的M2M(Machine-To-Machine,机器对机器通信)服务层的技术规范。oneM2M的核心是数据共享,具体是通过oneM2M CSE(Common Services Entity,公共服务实体)内定义的资源树上的数据项的共享实现的。
oneM2M通过对标准化的资源树进行操作来实现服务层资源的共享和交互,oneM2M资源树存在于oneM2M系统所定义的CSE中。根据oneM2M功能架构规范(oneM2M TS-0001:"Functional Architecture")中的定义,oneM2M资源树的形式如图1所示。对oneM2M资源可进行创建(Create)、查询(Retrieve)、修改(Update)和删除(Delete)等操作。
oneM2M所定义的资源中与授权相关的资源是访问控制策略资源<accessControlPolicy>,其中定义有ACP(Access Control Policy,访问控制策略)。<accessControlPolicy>资源由资源ID唯一标识,其他资源通过accessControlPolicyIDs属性指定所适用的访问控制策略。
目前,oneM2M系列规范中的安全规范(oneM2M TS-0003:"Security Solutions")给出了oneM2M授权架构的高层描述,具体给出了授权架构的主要组成部分和基本流程,但尚未在资源结构层面给出具体的分布式授权管理方案。
发明内容
本申请实施例提供了分布式授权管理方法及装置,在资源结构层面给出了分布式授权管理方案。
本申请实施例提供的分布式授权管理方法,包括:
PEP根据接收到的资源访问请求获取资源,该资源中包含用于承载授权实体地址的属性;
所述PEP根据所述资源中用于承载授权实体地址的属性获取授权实体地址,所述授权实体包括PDP、PRP、PIP中的一种或多种;
所述PEP根据获取到的授权实体地址,从该授权实体地址对应的授权实体获取用于执行访问控制决策的信息;
所述PEP根据获取到的用于执行访问控制决策的信息,针对所述资源访问请求执行访问控制决策。
优选地,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;
PEP根据所述资源中用于承载授权实体地址的属性获取PDP地址,包括:
若所述PEP未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略,则根据该资源中用于承载授权实体地址的属性获取PDP地址。
优选地,PEP根据接收到的资源访问请求获取资源,该资源中包含用于承载授权实体地址的属性,包括:
所述PEP根据接收到的资源访问请求,获取所请求访问的目标资源适用的访问控制策略资源;
若所述PEP未从所述访问控制策略资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PDP接入点属性,所述PDP接入点属性用于承载一个或多个PDP地址。
其中,若PDP接入点属性中承载有多个PDP地址,则所述PEP根据所述资源中用于承载授权实体地址的属性获取PDP地址,包括:所述PEP根据所述资源中的PDP接入点属性获取PDP地址,并从获取到的PDP地址中选择一个PDP地址。
本申请另一实施例提供的分布式授权管理方法,包括:
PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;
所述PDP根据所述资源中用于承载授权实体地址的属性获取PRP地址;
所述PDP根据获取到的PRP地址,从该PRP地址对应的PRP获取访问控制策略;
所述PDP根据获取到的访问控制策略进行访问控制决策。
优选地,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;
所述PDP根据所述资源中用于承载授权实体地址的属性获取PRP地址,包括:
若所述PDP未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略,则根据该资源中用于承载授权实体地址的属性获取PRP地址。
优选地,所述PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性,包括:
所述PDP根据接收到的访问控制决策请求,获取所请求访问的目标资源适用的访问控制策略资源;
若所述PEP未从所述访问控制策略资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PRP接入点属性,所述PRP接入点属性用于承载一个或多个PRP地址。
其中,若PRP接入点属性中承载有多个PRP地址,则所述PDP根据所述资源中用于承载授权实体地址的属性获取PRP地址,包括:所述PDP根据所述资源中的PRP接入点属性获取多个PRP地址,并从获取到的PRP地址中选择一个PRP地址。
本申请另一实施例提供的分布式授权管理方法,包括:
PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;
所述PDP根据所述资源中用于承载授权实体地址的属性获取PIP地址;
所述PDP根据获取到的PIP地址,从对应的PIP获取访问控制信息;
所述PDP根据获取到的访问控制信息进行访问控制决策。
优选地,所述PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性,包括:所述PDP根据接收到的访问控制决策请求,在所述PDP本地未获取到所需的访问控制信息,则获取所请求访问的目标资源适用的包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PIP接入点属性,所述PIP接入点属性用于承载一个或多个PIP地址。
其中,若PIP接入点属性中承载有多个PIP地址,则所述PDP根据所述资源中用于承载授权实体地址的属性获取PIP地址,包括:所述PDP根据所述资源中的PIP接入点属性获取PIP地址,并从获取到的PIP地址中选择一个PIP地址。
本申请实施例提供的PEP设备,包括:
第一获取模块,用于根据接收到的资源访问请求获取资源,该资源中包含用于承载授权实体地址的属性;
第二获取模块,用于根据所述资源中用于承载授权实体地址的属性获取授权实体地址,所述授权实体包括PDP、PRP、PIP中的一种或多种;
第三获取模块,用于根据获取到的授权实体地址,从该授权实体地址对应的授权实体获取用于执行访问控制决策的信息;
决策执行模块,用于根据获取到的用于执行访问控制决策的信息,针对所述资源访问请求执行访问控制决策。
优选地,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;所述第二获取模块具体用于:若未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略,则根据该资源中用于承载授权实体地址的属性获取PDP地址;或者,
所述第一获取模块具体用于:根据接收到的资源访问请求,获取所请求访问的目标资源适用的访问控制策略资源,若未从该资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PDP接入点属性,所述PDP接入点属性用于承载一个或多个PDP地址。
本申请实施例提供的PDP设备,包括:
第一获取模块,用于根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;
第二获取模块,用于根据所述资源中用于承载授权实体地址的属性获取PRP地址;
第三获取模块,用于根据获取到的PRP地址,从该PRP地址对应的PRP获取访问控制策略;
决策模块,用于根据获取到的访问控制策略进行访问控制决策。
优选地,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;所述第二获取模块具体用于:若未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略,则根据该资源中用于承载授权实体地址的属性获取PRP地址;或者,
所述第一获取模块具体用于:根据接收到的访问控制决策请求,获取所请求访问的目标资源适用的访问控制策略资源,若未从该资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PRP接入点属性,所述PRP接入点属性用于承载一个或多个PRP地址。
本申请另一实施例提供的PDP设备,包括:
第一获取模块,用于根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;
第二获取模块,用于根据所述第一资源中用于承载授权实体地址的属性获取PIP地址;
所述第三获取模块,用于根据获取到的PIP地址,从对应的PIP获取访问控制信息;
决策模块,用于根据获取到的访问控制信息进行访问控制决策。
优选地,所述第一获取模块具体用于:根据接收到的访问控制决策请求,在所述PDP本地未获取到所需的访问控制信息,则获取所请求访问的目标资源适用的包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PIP接入点属性,所述PIP接入点属性用于承载一个或多个PIP地址。
本申请的上述实施例中,授权实体根据包含有用于承载授权实体地址的属性的资源中用于承载授权实体地址的属性获取其他授权实体的地址,从而基于该地址从其他授权实体获取相应信息,在资源结构层面给出了分布式授权管理方案。
图1为现有技术中的oneM2M资源树示意图;
图2为现有技术中的oneM2M授权架构示意图;
图3为本申请实施例中定义的<accessControlPolicy>资源的结构示意图;
图4和图5分别为本申请实施例提供的基于PDP-PoAs属性实现的PEP与PDP之间的交互过程示意图;
图6和图7分别为本申请实施例提供的基于PRP-PoAs属性实现的PDP与PRP之间的交互过程示意图;
图8和图9分别为本申请实施例提供的基于PIP-PoAs属性实现的PDP与PIP之间的交互过程示意图;
图10为本申请实施例提供的具体应用场景示意图;
图11为本申请实施例提供的PEP结构示意图;
图12为本申请实施例提供的PDP结构示意图之一;
图13为本申请实施例提供的PDP结构示意图之二。
为了使本申请的目的、技术方案和优点更加清楚,下面将结合附图对本申请作进一步地详细描述,显然,所描述的实施例仅仅是本申请一部份实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其它实施例,都属于本申请保护的范围。
oneM2M定义了两种基本实体:应用实体(Application Entity,AE)和公共服务实体(Common Services Entity,CSE)。
AE位于应用层,可实现一个M2M应用逻辑。一个应用逻辑既可以驻留在多个M2M节点中,也可以在单个节点中存在多个执行实例。应用逻辑的每个执行实例被称为一个
AE,每个AE由唯一的AE-ID所标识。
CSE由一组M2M环境中的“公共服务功能(common service functions)”构成。每个CSE由唯一的CSE-ID所标识。oneM2M资源树存在于CSE中。
oneM2M定义了3种类型的资源:
普通资源(Normal Resource):具有具体的资源结构及资源属性。
虚拟资源(Virtual Resource):不具有具体的资源结构及资源属性,主要用于触发特定的处理过程。
公布资源(Announced Resource):具有具体的资源结构及属性,该资源为其他实体上普通资源某些内容的拷贝,主要目的是为资源发现提供便利。
oneM2M安全解决方案技术规范(oneM2M TS-0003:Security Solutions)中给出的授权架构如图2所示,该架构中可包括如下组件:
· 策略执行点(Policy Enforcement Point,PEP):PEP与需要访问控制的应用系统共存,并由应用系统调用,PEP将根据资源访问发起方的资源访问请求生成访问控制决策请求,并发送给PDP,然后根据PDP返回的访问控制决策响应确定是否执行该资源访问请求。
· 策略决策点(Policy Decision Point,PDP):PDP负责根据访问控制策略判决是否同意对由PEP发送来的访问控制决策请求所请求的目标资源进行访问,并将判决结果通过访问控制决策响应返回给PEP。
· 策略获取点(Policy Retrieval Point,PRP):PRP根据PDP提供的访问控制策略请求获取适用的访问控制策略,并将获取的访问控制策略返回给PDP。
· 策略信息点(Policy Information Point,PIP):PIP根据PDP的访问控制信息请求获取与用户、资源或环境相关的属性,例如访问用户的IP地址,资源的创建者,当前的时间等,然后将获得的属性返回给PDP。
oneM2M的基本资源访问控制流程可包括:
资源访问发起方向PEP发送资源访问请求(Access Request),PEP根据该资源访问请求向PDP发送访问控制决策请求(Decision Request)。
PDP根据PEP发送的访问控制决策请求向PRP发送访问控制策略请求(Policy Request),PRP向PDP返回访问控制策略响应(Policy Response),该访问控制策略响应中包含有访问控制策略。
PDP对访问控制决策请求和访问控制策略中包含的内容进行分析、判决;在进行分析、判决时,若需要其他属性,则向PIP发送访问控制信息请求(Attribute Request),PIP向PDP发送访问控制信息响应,该访问控制信息响应中包括根据访问控制信息请求获取到的与访问控制相关的属性。
PDP向PEP发送访问控制决策响应(Decision Response),该问控制决策响应中包括访问控制决策结果。PEP根据访问控制决策响应中的访问控制决策结果,决定是否执行资源访问发起方的资源访问请求。
为了在资源结构层面给出分布式授权管理方案,本申请实施例中对oneM2M中已定义的<accessControlPolicy>资源类型进行了重新定义,以便其能为分布式授权系统提供授权实体的地址信息。新定义的<accessControlPolicy>资源除能完成原有的功能外,还能在分布式授权的情况下,根据新定义的<accessControlPolicy>资源确定应该向哪个或哪些授权相关的实体发送相应的与授权相关的请求,也即向访问控制系统提供有关PDP、PRP或PIP的地址信息。
重新定义的<accessControlPolicy>资源的基本结构如图3所示。图3中用“0..n”表示属性或子资源可能的数量,n为大于等于1的整数;用“L”表示属性值可以是列表(List)形式。
本申请实施例在<accessControlPolicy>资源中新增加了三个资源属性:
PDP接入点属性:用于承载一组(即一个或多个)可实现PDP功能的实体的地址;该属性的属性名称可表示为可表示为PDP-PoAs或pdpAddresses,属性值为;一组可实现PDP功能的实体的地址,比如一个PDP地址列表;PDP-PoAs属性为可选属性。其中,PoA为Point of Access的缩略语,意为接入点;
PRP接入点属性:用于承载一组(即一个或多个)可实现PRP功能的实体的地址;该属性的属性名称可表示为PRP-PoAs或prpAddresses,属性值为一组可实现PRP功能的实体的地址,比如一个PRP地址列表;PRP-PoAs属性为可选属性;
PIP接入点属性:用于承载一组(即一个或多个)可实现PIP功能的实体的地址;该属性的属性名称可表示为PIP-PoAs或pipAddresses,属性值为一组可实现PIP功能的实体的地址,比如一个PIP地址列表;PIP-PoAs属性为可选属性。
进一步地,<accessControlPolicy>资源中还可包括以下已定义的属性中的一种或多种:
privileges属性:用于承载访问控制策略;
selfPrivileges属性:用于承载访问控制策略。
进一步地,可将上述privileges属性从原来的“必选”调整为“可选”。进一步地,如果<accessControlPolicy>资源中包含privileges属性,则其数量可以是一个或多个。
进一步地,<accessControlPolicy>资源中还可包含子资源,表示为<subscription>。<accessControlPolicy>资源中所包含的<subscription>资源的数量可以是一个或多个。<subscription>可以是oneM2M已定义的子资源。
上述实施例中,通过对<accessControlPolicy>资源重新定义,用新增加的资源属性承载授权实体的地址,进而可根据<accessControlPolicy>资源实现分布式授权管理。与此类似地,
在其他一些实施例中,也可保持现有技术中已定义的<accessControlPolicy>资源不变,而将上述3种资源属性(如PDP-PoAs属性、PRP-PoAs属性和PIP-PoAs属性)中的一种或多种组织在一个单独定义的新资源中,例如,该新定义的资源可命名为<authorizationEntity>。与<accessControlPolicy>资源处理方式类似,对于不能直接拥有<authorizationEntity>子资源类型的资源,可以通过公共资源属性(Common attribute)<authorizationEntityID>与某个<authorizationEntity>资源相关联。<authorizationEntity>资源中的资源属性的使用与其在<accessControlPolicy>资源类型中的方式相同。
可选地,现有技术中已定义的<accessControlPolicy>资源和本申请实施例定义的<authorizationEntity>资源使用的优先级顺序可以是:<accessControlPolicy>资源的优先级高于<authorizationEntity>资源的优先级。
下面以重新定义的<accessControlPolicy>资源为例,对本申请实施例提供的分布式授权管理流程进行说明。上述原理和处理方式同样适用于根据新定义的<authorizationEntity>资源实现分布式授权管理的过程。
参见图4,为本申请实施例提供的基于新定义的用于承载授权实体地址的属性实现PEP与PDP之间的交互的过程,如图所示,该流程可包括如下步骤:
步骤401:PEP根据接收到的资源访问请求获取资源,该资源中包含用于承载授权实体地址的属性(以下为描述方便将该资源称为第一资源)。
步骤402:PEP根据第一资源中用于承载授权实体地址的属性获取授权实体地址。所述授权实体包括可PDP、PRP、PIP中的一种或多种。具体地,PEP可根据第一资源中的PDP-PoAs属性获取PDP地址,根据第一资源中的PRP-PoAs属性获取PRP地址,根据第一资源中的PIP-PoAs属性获取PIP地址。
步骤403:PEP根据获取到的授权实体地址,从该授权实体地址对应的授权实体获取用于执行访问控制决策的信息。
该步骤中,PEP根据获取到的PDP地址,向对应的PDP发送访问控制决策请求;PDP接收到该访问控制决策请求后,根据目标资源采用相应的访问控制策略进行访问控制决策,并将访问控制决策信息(即决策结果)携带于访问控制决策响应中发送给该PEP。
PEP可根据获取到的PRP地址,向对应的PRP发送访问控制策略请求;PRP接收到该访问控制策略请求后,获取访问控制策略,并将访问控制策略携带于访问控制策略响应中发送给该PEP。
PEP可根据获取到的PIP地址,向对应的PIP发送访问控制信息请求;PIP接收到该访问控制信息请求后,获取访问控制信息,并将访问控制信息携带于访问控制信息响应中发送给该PEP。
步骤404:PEP根据获取到的用于执行访问控制决策的信息,针对所述资源访问请求
执行访问控制决策。
作为一个例子,上述流程中的第一资源为上述重新定义的<accessControlPolicy>资源。步骤401中,PEP根据接收到的资源访问请求,获取所请求访问的目标资源适用的<accessControlPolicy>资源;步骤402中,PEP获取<accessControlPolicy>资源的privileges属性值,该属性值即为访问控制策略,若PEP未从<accessControlPolicy>资源中获取到访问控制策略(比如在<accessControlPolicy>资源中未包含privileges属性的情况下,或者在<accessControlPolicy>资源中包含privileges属性但该属性的值为空的情况下,PEP无法从<accessControlPolicy>资源中获取到访问控制策略),则根据<accessControlPolicy>资源中的PDP-PoAs属性获取PDP地址。
作为另一个例子,上述流程中的第一资源为上述重新定义的<authorizationEntity>资源,第二资源为现有技术中的<accessControlPolicy>资源。步骤401中,PEP根据接收到的资源访问请求,获取所请求访问的目标资源适用的<accessControlPolicy>资源,PEP获取<accessControlPolicy>资源的privileges属性值,该属性值即为访问控制策略,若PEP未从<accessControlPolicy>资源中获取到访问控制策略(比如在<accessControlPolicy>资源中未包含privileges属性的情况下,或者在<accessControlPolicy>资源中包含privileges属性但该属性的值为空的情况下,PEP无法从<accessControlPolicy>资源中获取到访问控制策略),则获取<authorizationEntity>资源。如上所述,<authorizationEntity>资源中可包含上述的PDP-PoAs属性、PRP-PoAs属性和PIP-PoAs属性,这三种属性均为可选属性。
下面以基于新定义的<accessControlPolicy>资源为例,结合图5描述图4的一种具体实现过程。如图5所述,该流程可包括如下步骤:
步骤501:位于宿主CSE(Hosting CSE)中的PEP截取到来自于资源访问发起方(Originator)的资源访问请求后,按oneM2M系统的规定检索到目标资源适用的<accessControlPolicy>资源。
步骤502:PEP检查<accessControlPolicy>资源中是否包含有privileges属性且属性值不为空。若不包含有privileges属性或属性值为空,则转入步骤503;若包含有privileges属性且属性值不为空,则转入步骤506;
步骤503:PEP检查<accessControlPolicy>资源中是否包含有PDP-PoAs属性且属性值不为空。若包含有PDP-PoAs属性且属性值不为空,则转入步骤504;若不包含有PDP-PoAs属性或属性值为空,则转入步骤507;
步骤504:PEP读取PDP-PoAs属性中的PDP地址列表,并获得一个PDP地址(即PoA),然后转入步骤505;
步骤505:PEP生成访问控制决策请求(Access Control Decision Request),并将其发送给该PDP地址对应的PDP,从该PDP接收返回的访问控制决策响应(Access Control
Decision Response),该访问控制决策响应中包含访问控制决策信息,然后转入步骤508;
步骤506:PEP读取privileges属性中的访问控制策略,并利用其评估发起方的资源访问请求,进而获得访问控制决策,然后转入步骤508;
步骤507:PEP进行出错处理,然后转入步骤508;
步骤508:PEP执行访问控制决策,并结束本次访问控制过程。其中,如果是从步骤507转入到步骤508的,则由于步骤507中进行了出错处理,则在步骤508中,PEP可拒绝资源访问发起方(Originator)的资源访问请求,或者按照预先约定进行处理。
参见图6,为本申请实施例提供的基于新定义的PRP接入点属性(以下称为PRP-PoAs属性)实现PDP与PRP之间的交互的过程,如图所示,该流程可包括如下步骤:
步骤601:PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性(以下为描述方便将该资源称为第一资源);
步骤602:PDP根据第一资源中用于承载授权实体地址的属性获取PRP地址。具体地,PEP根据第一资源中的PRP-PoAs属性获取PRP地址。
步骤603:PDP根据获取到的PRP地址,从该PRP地址对应的PRP获取访问控制策略。
该步骤中,PDP根据获取到的PRP地址,向对应的PRP发送访问控制策略请求;PRP接收到该访问控制策略请求后,获取访问控制策略,并将访问控制策略携带于访问控制策略响应中发送给该PDP。
步骤604:PDP根据获取到的访问控制策略进行访问控制决策。
作为一个例子,上述流程中的第一资源为上述重新定义的<accessControlPolicy>资源。步骤601中,PDP根据接收到的访问控制策略请求,获取所请求访问的目标资源适用的<accessControlPolicy>资源;步骤602中,PDP获取<accessControlPolicy>资源的privileges属性值,该属性值即为访问控制策略,若PDP未从<accessControlPolicy>资源中获取到访问控制策略(比如在<accessControlPolicy>资源中未包含privileges属性的情况下,或者在<accessControlPolicy>资源中包含privileges属性但该属性的值为空的情况下,PDP无法从<accessControlPolicy>资源中获取到访问控制策略),则根据<accessControlPolicy>资源中的PRP-PoAs属性获取PRP地址。
作为另一个例子,上述流程中的第一资源为上述重新定义的<authorizationEntity>资源,第二资源为现有技术中的<accessControlPolicy>资源。步骤601中,PDP根据接收到的访问控制策略请求,获取所请求访问的目标资源适用的<accessControlPolicy>资源,PDP获取<accessControlPolicy>资源的privileges属性值,该属性值即为访问控制策略,若PDP未从<accessControlPolicy>资源中获取到访问控制策略(比如在<accessControlPolicy>资源中未包含privileges属性的情况下,或者在<accessControlPolicy>资源中包含privileges属性但该
属性的值为空的情况下,PDP无法从<accessControlPolicy>资源中获取到访问控制策略),则获取<authorizationEntity>资源。如上所述,<authorizationEntity>资源中可包含上述的PDP-PoAs属性、PRP-PoAs属性和PIP-PoAs属性,这三种属性均为可选属性。
下面以基于新定义的<accessControlPolicy>资源为例,结合图7描述图6的一种具体实现过程。如图7所述,该流程可包括如下步骤:
步骤701:PDP收到来自于PEP的访问控制决策请求后,利用访问控制决策请求中的目标资源地址检索适用的<accessControlPolicy>资源。
步骤702:PDP检查<accessControlPolicy>资源中是否包含有privileges属性且属性值不为空。若不包含有privileges属性或属性值为空,则转入步骤703;若包含有privileges属性且属性值不为空,则转入步骤706;
步骤703:PDP检查<accessControlPolicy>资源中是否包含有PRP-PoAs属性且属性值不为空。若包含PRP-PoAs属性且属性值不为空,则转入步骤704;若不包含有PRP-PoAs属性或属性值为空,则转入步骤707;
步骤704:PDP读取PRP-PoAs属性中的PRP地址列表,并获得一个PRP地址,然后转入步骤705;
步骤705:PDP生成访问控制策略请求(Access Control Policy Request),并将其发送给该PRP地址对应的PRP,从该PRP接收返回的访问控制策略响应(Access Control Policy Response),获取响应中的访问控制策略,然后转入步骤708;
步骤706:PDP读取privileges属性中的访问控制策略,然后转入步骤708;
步骤707:PDP进行出错处理,然后转入步骤708;
步骤708:PDP结束本次获取访问控制策略的过程。进一步地,PDP可根据获取到的访问控制策略进行访问控制决策。
参见图8,为本申请实施例提供的基于新定义的PIP接入点属性(以下称为PIP-PoAs属性)实现PDP与PIP之间的交互的过程,如图所示,该流程可包括如下步骤:
步骤801:PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性(以下为描述方便将该资源称为第一资源);
步骤802:PDP根据第一资源中用于承载授权实体地址的属性获取PIP地址。具体地,PEP根据第一资源中的PIP-PoAs属性获取PIP地址。
步骤803:PDP根据获取到的PIP地址,从对应的PIP获取访问控制信息。
该步骤中,PDP根据获取到的PIP地址,向对应的PIP发送访问控制信息请求;PIP接收到该访问控制信息请求后,获取访问控制信息,并将访问控制信息携带于访问控制信息响应中发送给该PDP。
步骤804:PDP根据获取到的访问控制信息进行访问控制决策。
作为一个例子,上述流程中的第一资源为上述重新定义的<accessControlPolicy>资源。步骤801中,PDP根据接收到的访问控制策略请求,在所述PDP本地未获取到所需的访问控制信息,则获取所请求访问的目标资源适用的<accessControlPolicy>资源。
作为另一个例子,上述流程中的第一资源为上述重新定义的<authorizationEntity>资源,第二资源为现有技术中的<accessControlPolicy>资源。步骤801中,PDP根据接收到的访问控制策略请求,在所述PDP本地未获取到所需的访问控制信息,则获取所请求访问的目标资源适用的<authorizationEntity>资源。如上所述,<authorizationEntity>资源中可包含上述的PDP-PoAs属性、PRP-PoAs属性和PIP-PoAs属性,这三种属性均为可选属性。
下面以基于新定义的<accessControlPolicy>资源为例,结合图9描述图8的一种具体实现过程。如图9所述,该流程可包括如下步骤:
步骤901:PDP收到来自于PEP的访问控制决策请求后,检查访问控制决策请求中的参数,确定是否有本地不能提供的访问控制信息,例如角色标识或令牌标识等。若有,则转入步骤902;否则转入步骤907;
步骤902:PDP利用访问控制决策请求中的目标资源地址检索适用的<accessControlPolicy>资源。
步骤903:PDP检查<accessControlPolicy>资源中是否包含有PIP-PoAs属性且属性值不为空。若包含有PIP-PoAs属性且属性值不为空,则转入步骤904;若不包含有PIP-PoAs属性或属性值为空,则转入步骤906;
步骤904:PDP读取有PIP-PoAs属性中的PIP地址列表,并获得一个PIP地址,然后转入步骤905;
步骤905:PDP生成访问控制信息请求(Access Control Information Request),并将其发送给该PIP,并从该PIP接收返回的访问控制信息响应(Access Control Information Response),获取该响应中的访问控制信息,然后转入步骤907;
步骤906:PDP进行出错处理,然后执行步骤907;
步骤907:PDP结束本次获取访问控制信息过程。进一步地,PDP可根据获取到的访问控制信息进行访问控制决策。
为了更清楚地理解本申请实施例,下面以一个具体应用场景为例对本申请实施例提供的分布式授权管理方案进行说明。
该场景中,oneM2M应用服务提供商(oneM2M Application Service Provider)通过oneM2M服务商(oneM2M Service Provider)提供的oneM2M平台读取安装在用户家中的物联网设备。具体场景如图10所示。其中,CSE0为oneM2M服务商的基础设施节点;CSE1为用户的家庭网关;CSE2、CSE3和CSE4为用户家中的物联网设备;AE1为oneM2M应用服务提供商注册至CSE0的应用服务实体;其中,CSE2、CSE3和CSE4的访问控制策
略和访问控制决策点均设置在CSE1中;AE1通过角色访问CSE2、CSE3和CSE4中的资源。
系统资源及参数配置如下:
CSE2、CSE3和CSE4中的访问控制策略资源(<accessControlPolicy>资源)中的privileges属性均为空,但PDP-PoAs属性设置为指向CSE1(即PDP-PoAs属性的属性值中包含CSE1的地址);
CSE1中的访问控制策略资源(<accessControlPolicy>资源)中的PIP-PoAs属性设置为指向CSE0(即PDP-PoAs属性的属性值中包含CSE0的地址);
CSE0中存储有AE1的角色信息。
基于上述架构以及系统配置,分布式授权访问控制的过程可包括:
AE1向CSE2资源树发送数据读取指令,其中包含有角色标识;
CSE2检查本地的访问控制策略,发现与该资源相关联的访问控制资源的privileges属性为空,但PDP-PoAs不为空,且指向CSE1,于是生成一个访问控制决策请求,并发送给CSE1;
CSE1检查存储在本地的针对目标资源的访问控制策略资源,并获得访问控制策略;
CSE1检查CSE2发送来的访问控制决策请求,发现其中包含有角色标识;其检查存储在本地的针对目标资源的访问控制策略资源,发现PIP-PoAs不为空且指向CSE0,于是生成一个访问控制信息请求,并发送给CSE0;
CSE0根据CSE1的访问控制信息请求检索到相关的角色信息,并将其通过访问控制信息响应返回给CSE1;
CSE1根据访问控制策略和AE1的角色信息评估AE1的资源访问请求,并将访问控制决策通过访问控制决策响应返回给CSE2;
CSE2根据访问控制决策决定是否执行AE1的资源访问请求。
通过以上描述可以看出,授权实体根据本申请实施例定义的资源(该资源中包含用于承载授权实体地址的资源属性)中用于承载授权实体地址的属性获取其他授权实体的地址,从而基于该地址从其他授权实体获取相应信息,在资源结构层面给出了分布式授权管理方案。
基于相同的技术构思,本申请实施例还提供了一种PEP。
参见图11,为本申请实施例提供的PEP的结构示意图,该PEP可实现本申请上述实施例提供的相关流程。如图所示,该PEP可包括:第一获取模块1101、第二获取模块1102、第三获取模块1103、决策执行模块1104,其中:
第一获取模块1101,用于根据接收到的资源访问请求获取资源,该资源中包含用于承载授权实体地址的属性;
第二获取模块1102,用于根据所述资源中用于承载授权实体地址的属性获取授权实体地址,所述授权实体包括PDP、PRP、PIP中的一种或多种;
第三获取模块1103,用于根据获取到的授权实体地址,从该授权实体地址对应的授权实体获取用于执行访问控制决策的信息;
决策执行模块1104,用于根据获取到的用于执行访问控制决策的信息,针对所述资源访问请求执行访问控制决策。
优选地,在一些实施例中,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;;第二获取模块1102可具体用于:若未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略,则根据该资源中用于承载授权实体地址的属性获取PDP地址。
优选地,在另一些实施例中,第一获取模块1101可具体用于:根据接收到的资源访问请求,获取所请求访问的目标资源适用的访问控制策略资源;若未从该资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PDP接入点属性,所述PDP接入点属性用于承载一个或多个PDP地址。
基于相同的技术构思,本申请实施例还提供了一种PDP。
参见图12,为本申请实施例提供的PDP的结构示意图,该PDP可实现本申请上述实施例提供的相关流程。如图所示,该PDP可包括:第一获取模块1201、第二获取模块1202、第三获取模块1203、决策模块1204,其中:
第一获取模块1201,用于根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;
第二获取模块1202,用于根据所述资源中用于承载授权实体地址的属性获取PRP地址;
第三获取模块1203,用于根据获取到的PRP地址,从该PRP地址对应的PRP获取访问控制策略;
决策模块1204,用于根据获取到的访问控制策略进行访问控制决策。
优选地,在一些实施例中,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;第二获取模块1202具体用于:若未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略,则根据该资源中用于承载授权实体地址的属性获取PRP地址.
优选地,在另一些实施例中,第一获取模块1201具体用于:根据接收到的访问控制决策请求,获取所请求访问的目标资源适用的访问控制策略资源;若所述PEP未从该资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PRP接入点属性,所述PRP接入点属性用于承载一个或多个PRP地址。
基于相同的技术构思,本申请实施例还提供了一种PDP。
参见图13,为本申请实施例提供的PDP的结构示意图,该PDP可实现本申请上述实施例提供的相关流程。如图所示,该PDP可包括:第一获取模块1301、第二获取模块1302、第三获取模块1303、决策模块1304,其中:
第一获取模块1301,用于根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;
第二获取模块1302,用于根据所述资源中用于承载授权实体地址的属性获取策略信息点PIP地址;
所述第三获取模块1303,用于根据获取到的PIP地址,从对应的PIP获取访问控制信息;
决策模块1304,用于根据获取到的访问控制信息进行访问控制决策。
优选地,第一获取模块1301具体用于:根据接收到的访问控制决策请求,在所述PDP本地未获取到所需的访问控制信息,则获取所请求访问的目标资源适用的包含有用于承载授权实体地址的属性的资源。
优选地,所述用于承载授权实体地址的属性包括:PIP接入点属性,所述PIP接入点属性用于承载一个或多个PIP地址。
本申请实施例中上述任一模块,均可以由处理器或具有收发功能的处理器等实体模块实现。
综上所述,目前oneM2M只定义了授权系统的高层架构,并未提供具体的解决方案。本申请实施例提供了一种在oneM2M系统中实现分布式授权系统管理的方案。本申请实施例通过重新定义oneM2M<accessControlPolicy>资源类型,将所需的功能加入其中,避免新建资源类型以及对TS的大量修改。
本申请是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装
置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
尽管已描述了本申请的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例作出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本申请范围的所有变更和修改。
显然,本领域的技术人员可以对本申请进行各种改动和变型而不脱离本申请的精神和范围。这样,倘若本申请的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。
Claims (25)
- 一种分布式授权管理方法,其特征在于,包括:策略执行点PEP根据接收到的资源访问请求获取资源,该资源中包含用于承载授权实体地址的属性;所述PEP根据所述资源中用于承载授权实体地址的属性获取授权实体地址;所述PEP根据获取到的授权实体地址,从该授权实体地址对应的授权实体获取用于执行访问控制决策的信息;所述PEP根据获取到的用于执行访问控制决策的信息,针对所述资源访问请求执行访问控制决策。
- 如权利要求1所述的方法,其特征在于,所述授权实体包括策略决策点PDP、策略获取点PRP、策略信息点PIP中的一种或多种。
- 如权利要求2所述的方法,其特征在于,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;若所述授权实体包括PDP,则所述PEP根据所述资源中用于承载授权实体地址的属性获取PDP地址,是在所述PEP未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略的情况下执行的。
- 如权利要求1所述的方法,其特征在于,所述PEP根据接收到的资源访问请求获取资源,包括:所述PEP根据接收到的资源访问请求,获取所请求访问的目标资源适用的访问控制策略资源;若所述PEP未从所述访问控制策略资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
- 如权利要求2至4中任一项所述的方法,其特征在于,若所述授权实体包括PDP,则所述用于承载授权实体地址的属性包括:PDP接入点属性,所述PDP接入点属性用于承载一个或多个PDP地址。
- 如权利要求5所述的方法,其特征在于,若所述PDP接入点属性中承载有多个PDP地址,则所述PEP根据所述资源中用于承载授权实体地址的属性获取PDP地址,包括:所述PEP根据所述资源中的PDP接入点属性获取多个PDP地址,并从获取到的多个PDP地址中选择一个PDP地址。
- 一种分布式授权管理方法,其特征在于,包括:策略决策点PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;所述PDP根据所述资源中用于承载授权实体地址的属性获取策略获取点PRP地址;所述PDP根据获取到的PRP地址,从该PRP地址对应的PRP获取访问控制策略;所述PDP根据获取到的访问控制策略进行访问控制决策。
- 如权利要求7所述的方法,其特征在于,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;所述PDP根据所述资源中用于承载授权实体地址的属性获取PRP地址是在所述PDP未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略的情况下执行的。
- 如权利要求7所述的方法,其特征在于,所述PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性,包括:所述PDP根据接收到的访问控制决策请求,获取所请求访问的目标资源适用的访问控制策略资源;若所述PEP未从所述访问控制策略资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
- 如权利要求7至9中任一项所述的方法,其特征在于,所述用于承载授权实体地址的属性包括:PRP接入点属性,所述PRP接入点属性用于承载一个或多个PRP地址。
- 如权利要求10所述的方法,其特征在于,若PRP接入点属性中承载有多个PRP地址,则所述PDP根据所述资源中用于承载授权实体地址的属性获取PRP地址,包括:所述PDP根据所述资源中的PRP接入点属性获取多个PRP地址,并从获取到的多个PRP地址中选择一个PRP地址。
- 一种分布式授权管理方法,其特征在于,包括:策略决策点PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;所述PDP根据所述资源中用于承载授权实体地址的属性获取策略信息点PIP地址;所述PDP根据获取到的PIP地址,从对应的PIP获取访问控制信息;所述PDP根据获取到的访问控制信息进行访问控制决策。
- 如权利要求12所述的方法,其特征在于,所述PDP根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性,包括:所述PDP根据接收到的访问控制决策请求,在所述PDP本地未获取到所需的访问控制信息,则获取所请求访问的目标资源适用的包含有用于承载授权实体地址的属性的资源。
- 如权利要求12或13所述的方法,其特征在于,所述用于承载授权实体地址的属性包括:PIP接入点属性,所述PIP接入点属性用于承载一个或多个PIP地址。
- 如权利要求14所述的方法,其特征在于,若PIP接入点属性中承载有多个PIP地址,则所述PDP根据所述资源中用于承载授权实体地址的属性获取PIP地址,包括:所述PDP根据所述资源中的PIP接入点属性获取多个PIP地址,并从获取到的多个PIP地址中选择一个PIP地址。
- 一种策略执行点PEP设备,其特征在于,包括:第一获取模块,用于根据接收到的资源访问请求获取资源,该资源中包含用于承载授权实体地址的属性;第二获取模块,用于根据所述资源中用于承载授权实体地址的属性获取授权实体地址;第三获取模块,用于根据获取到的授权实体地址,从该授权实体地址对应的授权实体获取用于执行访问控制决策的信息;决策执行模块,用于根据获取到的用于执行访问控制决策的信息,针对所述资源访问请求执行访问控制决策。
- 如权利要求16所述的设备,其特征在于,所述授权实体包括策略决策点PDP、策略获取点PRP、策略信息点PIP中的一种或多种。
- 如权利要求16所述的设备,其特征在于,所述包含有用于承载授权实体地址的属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;所述第二获取模块具体用于:若未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略,则根据该资源中用于承载授权实体地址的属性获取PDP地址;或者,所述第一获取模块具体用于:根据接收到的资源访问请求,获取所请求访问的目标资源适用的访问控制策略资源,若未从该资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
- 如权利要求16或17或18所述的设备,其特征在于,所述用于承载授权实体地址的属性包括:PDP接入点属性,所述PDP接入点属性用于承载一个或多个PDP地址。
- 一种策略决策点PDP设备,其特征在于,包括:第一获取模块,用于根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;第二获取模块,用于根据所述资源中用于承载授权实体地址的属性获取策略获取点PRP地址;第三获取模块,用于根据获取到的PRP地址,从该PRP地址对应的PRP获取访问控制策略;决策模块,用于根据获取到的访问控制策略进行访问控制决策。
- 如权利要求20所述的设备,其特征在于,所述包含有用于承载授权实体地址的 属性的资源,为包含有用于承载授权实体地址的属性的访问控制策略资源;所述第二获取模块具体用于:若未从所述包含有用于承载授权实体地址的属性的访问控制策略资源中获取到访问控制策略,则根据该资源中用于承载授权实体地址的属性获取PRP地址;或者,所述第一获取模块具体用于:根据接收到的访问控制决策请求,获取所请求访问的目标资源适用的访问控制策略资源,若未从该资源中获取到访问控制策略,则获取所述包含有用于承载授权实体地址的属性的资源。
- 如权利要求20或21所述的设备,其特征在于,所述用于承载授权实体地址的属性包括:PRP接入点属性,所述PRP接入点属性用于承载一个或多个PRP地址。
- 一种策略决策点PDP设备,其特征在于,包括:第一获取模块,用于根据接收到的访问控制决策请求获取资源,该资源中包含用于承载授权实体地址的属性;第二获取模块,用于根据所述第一资源中用于承载授权实体地址的属性获取策略信息点PIP地址;所述第三获取模块,用于根据获取到的PIP地址,从对应的PIP获取访问控制信息;决策模块,用于根据获取到的访问控制信息进行访问控制决策。
- 如权利要求23所述的设备,其特征在于,所述第一获取模块具体用于:根据接收到的访问控制决策请求,在所述PDP本地未获取到所需的访问控制信息,则获取所请求访问的目标资源适用的包含有用于承载授权实体地址的属性的资源。
- 如权利要求23或24所述的设备,其特征在于,所述用于承载授权实体地址的属性包括:PIP接入点属性,所述PIP接入点属性用于承载一个或多个PIP地址。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610242998.5 | 2016-04-18 | ||
| CN201610242998.5A CN107306398A (zh) | 2016-04-18 | 2016-04-18 | 分布式授权管理方法及装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017181775A1 true WO2017181775A1 (zh) | 2017-10-26 |
Family
ID=60116508
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2017/075429 Ceased WO2017181775A1 (zh) | 2016-04-18 | 2017-03-02 | 分布式授权管理方法及装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN107306398A (zh) |
| WO (1) | WO2017181775A1 (zh) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111490966A (zh) * | 2019-01-28 | 2020-08-04 | 电信科学技术研究院有限公司 | 一种访问控制策略的处理方法、装置及计算机可读存储介质 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050166260A1 (en) * | 2003-07-11 | 2005-07-28 | Christopher Betts | Distributed policy enforcement using a distributed directory |
| CN103378987A (zh) * | 2012-04-24 | 2013-10-30 | 国际商业机器公司 | 用于对多个安全域进行策略管理的方法和系统 |
| WO2013161212A1 (en) * | 2012-04-26 | 2013-10-31 | International Business Machines Corporation | Policy-based dynamic information flow controlon mobile devices |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2011197903A (ja) * | 2010-03-18 | 2011-10-06 | Fujitsu Ltd | アクセス制御情報配布装置、アクセス制御情報配布プログラム、アクセス制御システム、及びアクセス制御情報配布方法 |
| CN102006297B (zh) * | 2010-11-23 | 2013-04-10 | 中国科学院软件研究所 | 一种基于两级策略决策的访问控制方法及其系统 |
| CN104811465B (zh) * | 2014-01-27 | 2018-06-01 | 电信科学技术研究院 | 一种访问控制的决策方法和设备 |
| CN104735055B (zh) * | 2015-02-12 | 2018-09-21 | 河南理工大学 | 一种基于信任度的跨域安全访问控制方法 |
-
2016
- 2016-04-18 CN CN201610242998.5A patent/CN107306398A/zh active Pending
-
2017
- 2017-03-02 WO PCT/CN2017/075429 patent/WO2017181775A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050166260A1 (en) * | 2003-07-11 | 2005-07-28 | Christopher Betts | Distributed policy enforcement using a distributed directory |
| CN103378987A (zh) * | 2012-04-24 | 2013-10-30 | 国际商业机器公司 | 用于对多个安全域进行策略管理的方法和系统 |
| WO2013161212A1 (en) * | 2012-04-26 | 2013-10-31 | International Business Machines Corporation | Policy-based dynamic information flow controlon mobile devices |
Non-Patent Citations (1)
| Title |
|---|
| "oneM2M; Security solutions (oneM2M TS-0003 version 1.4.2 Release 1", ETSI TS 118 103, 31 March 2016 (2016-03-31), pages 21 - 25, XP055433737 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN107306398A (zh) | 2017-10-31 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN108353094B (zh) | 用于m2m服务层的跨资源订阅 | |
| CN109716296B (zh) | 通过相关联容器的应用令牌 | |
| US8856909B1 (en) | IF-MAP provisioning of resources and services | |
| CN107784221B (zh) | 权限控制方法、服务提供方法、装置、系统及电子设备 | |
| US11902279B2 (en) | Method, apparatus, system and storage medium for access control policy configuration | |
| US9900775B2 (en) | On-device authorization of devices for collaboration and association | |
| JP2018533857A (ja) | サービス層動的承認 | |
| WO2017024791A1 (zh) | 一种处理授权的方法和设备 | |
| JP2018521399A (ja) | コマンド実行に対するユーザアクセスの制御 | |
| US9479490B2 (en) | Methods and systems for single sign-on while protecting user privacy | |
| CN107005571A (zh) | 基于权限的资源和服务发现 | |
| US12106253B2 (en) | Container management method, apparatus, and device | |
| CN115361183A (zh) | 一种代理订阅的授权方法及装置 | |
| CN110363026A (zh) | 文件操作方法、装置、设备、系统及计算机可读存储介质 | |
| CN107666505B (zh) | 对资源接入进行控制的方法和装置 | |
| CN106034112B (zh) | 访问控制、策略获取、属性获取方法及相关装置 | |
| CN107113182A (zh) | 用于在服务层处支持协商服务的方法 | |
| US10785056B1 (en) | Sharing a subnet of a logically isolated network between client accounts of a provider network | |
| WO2020248284A1 (zh) | 一种访问控制方法、装置及存储介质 | |
| US9537893B2 (en) | Abstract evaluation of access control policies for efficient evaluation of constraints | |
| CN105207974A (zh) | 一种实现用户资源差异化开放的方法、平台、应用和系统 | |
| KR20200047720A (ko) | 통신 네트워크에서의 서비스 계층 메시지 템플릿들 | |
| WO2017121240A1 (zh) | 一种资源访问控制方法、装置及系统 | |
| KR102561083B1 (ko) | 프로파일 기반 콘텐츠 및 서비스들 | |
| CN107306247B (zh) | 资源访问控制方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17785261 Country of ref document: EP Kind code of ref document: A1 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 17785261 Country of ref document: EP Kind code of ref document: A1 |