Secure Label-Based Data Sharing Mechanism for Multi-domain
摘要
In the context of power systems, multi-domain data sharing and interaction involve multiple organizations, applications, and processes. This scenario showcases frequent multi-domain data flows and complex pathways involving different data interaction entities. While traditional role-based and attribute-based access control techniques can effectively manage data access within a single domain or scenario, they often overlook dynamic factors such as time, location, and device. Furthermore, with the increasing diversity of access needs and data sensitivity, there is a growing demand for fine-grained access control. In multi-domain scenarios, it is challenging to assess the trustworthiness of third parties requesting data access. Ensuring that multi-domain data accessors can only obtain the data necessary to complete their business functions in a controlled manner is crucial. To secure data during inter-domain transfer, this paper proposes a multi-domain data sharing mechanism based on security labels. This mechanism involves designing labels based on XML documents, splitting data into multiple levels, manually defining the security levels of sensitive data, and binding attribute labels to the data. This approach aims to protect the privacy of sensitive data and enhance the precision and effectiveness of data access control, ensuring that data remains controlled during transmission and strengthening the management of multi-domain data transfers.