摘要:Access control service is used to solve the controllability problem of data and service, access control system is finally deployed in the form of policy. The description forms of policy are different in the stage of configuration and deployment. Safety policy translation model is used to realize configuration policy and automatic translation of deployment policy. However, currently it lacks automatic translation model. What’s more, automatic translation models are different according to different access control models. In this paper, a spatial access control model is proposed through the object-oriented idea. In addition, the spatial access control policy elements are declared, and they are translated through compiling principle. Finally, the configuration policy is translated to deployment policy which is described by XACML through the policy translation rules.
关键词:access control policy;spatial;policy translation model;XACML