BS DD IEC TS 62351-8-2011 Power systems management and associated information exchange Data and communications security Role-based access control《电力系统管理和相关信息交换 数据和通信安全 角色访问控制》.pdf
《BS DD IEC TS 62351-8-2011 Power systems management and associated information exchange Data and communications security Role-based access control《电力系统管理和相关信息交换 数据和通信安全 角色访问控制》.pdf》由会员分享,可在线阅读,更多相关《BS DD IEC TS 62351-8-2011 Power systems management and associated information exchange Data and communications security Role-based access control《电力系统管理和相关信息交换 数据和通信安全 角色访问控制》.pdf(47页珍藏版)》请在麦多课文档分享上搜索。
1、raising standards worldwideNO COPYING WITHOUT BSI PERMISSION EXCEPT AS PERMITTED BY COPYRIGHT LAWBSI Standards PublicationPower systems management and associated informationexchange Data and communications securityPart 8: Role-based access controlDD IEC/TS 62351-8:2011National forewordThis Draft for
2、 Development is the UK implementation of IEC/TS 62351-8:2011.The UK participation in its preparation was entrusted to Technical CommitteePEL/57, Power systems management and associated information exchange.A list of organizations represented on this committee can be obtained onrequest to its secreta
3、ry.This publication does not purport to include all the necessary provisions of acontract. Users are responsible for its correct application. BSI 2011ISBN 978 0 580 67829 5ICS 33.200 Compliance with a British Standard cannot confer immunity fromlegal obligations.This Draft for Development was publis
4、hed under the authority of theStandards Policy and Strategy Committee on 31 October 2011.Amendments issued since publicationAmd. No. Date Text affectedDRAFT FOR DEVELOPMENTDD IEC/TS 62351-8:2011IEC/TS 62351-8 Edition 1.0 2011-09 TECHNICAL SPECIFICATION Power systems management and associated informa
5、tion exchange Data and communications security Part 8: Role-based access control INTERNATIONAL ELECTROTECHNICAL COMMISSION X ICS 33.200 PRICE CODE ISBN 978-2-88912-723-8 Registered trademark of the International Electrotechnical Commission colourinsideDD IEC/TS 62351-8:2011 2 TS 62351-8 IEC:2011(E)
6、CONTENTS FOREWORD . 5 INTRODUCTION . 7 1 Scope . 8 2 Normative references 9 3 Terms, definitions and abbreviations . 10 3.1 Terms and definitions 10 3.2 Abbreviations . 12 4 RBAC process model 13 4.1 General . 13 4.2 Separation of subjects, roles, and rights. 14 4.2.1 General . 14 4.2.2 Subject assi
7、gnment 15 4.2.3 Role assignment 16 4.2.4 Right assignment . 16 4.3 Criteria for defining roles . 16 4.3.1 Policies 16 4.3.2 User, roles, and rights 16 4.3.3 Introducing roles reduces complexity 16 5 Definition of roles 17 5.1 Role-to-right assignment inside the object in general 17 5.1.1 General . 1
8、7 5.1.2 Number of supported rights 17 5.1.3 Number of supported roles . 17 5.1.4 Flexibility of role-to-right mapping 17 5.2 Role-to-right assignment with respect to power systems . 17 5.2.1 Mandatory roles and rights for logical-device access control . 17 5.2.2 Power utility automation IEC 61850 .
9、20 5.2.3 CIM IEC 61968 . 22 5.2.4 AMI 22 5.2.5 DER 22 5.2.6 Markets . 23 5.3 Role-to-right assignment with respect to other non-power system domains (e.g. industrial process control) 23 6 General architecture for the PUSH model 23 6.1 General . 23 6.2 Secure access to the LDAP-enabled service 24 7 G
10、eneral architecture for the PULL model . 24 7.1 General . 24 7.2 Secure access to the LDAP-enabled service 26 7.3 LDAP directory organization . 26 8 General application of RBAC access token . 26 8.1 General . 26 8.2 Session based approach 27 8.3 Message based approach 28 9 Definition of access token
11、s . 28 9.1 General . 28 DD IEC/TS 62351-8:2011TS 62351-8 IEC:2011(E) 3 9.2 Supported profiles . 29 9.3 Identification of access token . 29 9.4 General structure of the access tokens 29 9.4.1 Mandatory fields in the access tokens 29 9.4.2 Mandatory profile-specific fields . 29 9.4.3 Optional fields i
12、n the access tokens . 30 9.4.4 Definition of specific fields . 30 9.5 Specific structure of the access tokens 32 9.5.1 Profile A: X.509 ID certificate . 32 9.5.2 Profile B: X.509 attribute certificate 34 9.5.3 Profile C: Software token . 37 9.6 Distribution of the access tokens . 37 10 Transport pro
13、files . 38 10.1 Usage in TCP-based protocols . 38 10.2 Usage in non-Ethernet based protocols 38 11 Verification of access tokens. 38 11.1 Normative part . 38 11.1.1 General . 38 11.1.2 Access token authenticity . 38 11.1.3 Time period . 39 11.1.4 Access token integrity 39 11.2 Optional part 39 11.3
14、Revocation methods 39 11.3.1 General . 39 11.3.2 Supported methods 40 12 Interoperability 40 12.1 General . 40 12.2 Supported access tokens . 40 12.3 How to ensure backward compatibility 40 12.4 How to extend the list of roles and rights 41 12.5 How to map this specification to specific authorizatio
15、n mechanisms . 41 Bibliography 42 Figure 1 Generic framework for access control . 13 Figure 2 Diagram of RBAC with static and dynamic separation of duty according to (ANSI INCITS 359-2004) . 14 Figure 3 User, roles, rights and operations . 15 Figure 4 Schematic view of authorization mechanism based
16、on RBAC 24 Figure 5 Schematic view of authorization mechanism based on RBAC PULL model . 25 Figure 6 Session based RBAC approach 28 Table 1 List of pre-defined role-to-right assignment 18 Table 2 List of mandatory pre-defined rights . 19 Table 3 Pre-defined roles . 20 Table 4 Mandatory role-to-right
17、 mapping for service access control 21 Table 5 The ALLOW right . 21 Table 6 The DENY right 21 DD IEC/TS 62351-8:2011 4 TS 62351-8 IEC:2011(E) Table 7 VIEW right and associated ACSI services 22 Table 8 Mapping between ID and attribute certificate 36 DD IEC/TS 62351-8:2011TS 62351-8 IEC:2011(E) 5 INTE
18、RNATIONAL ELECTROTECHNICAL COMMISSION _ POWER SYSTEMS MANAGEMENT AND ASSOCIATED INFORMATION EXCHANGE DATA AND COMMUNICATIONS SECURITY Part 8: Role-based access control FOREWORD 1) The International Electrotechnical Commission (IEC) is a worldwide organization for standardization comprising all natio
19、nal electrotechnical committees (IEC National Committees). The object of IEC is to promote international co-operation on all questions concerning standardization in the electrical and electronic fields. To this end and in addition to other activities, IEC publishes International Standards, Technical
20、 Specifications, Technical Reports, Publicly Available Specifications (PAS) and Guides (hereafter referred to as “IEC Publication(s)”). Their preparation is entrusted to technical committees; any IEC National Committee interested in the subject dealt with may participate in this preparatory work. In
21、ternational, governmental and non-governmental organizations liaising with the IEC also participate in this preparation. IEC collaborates closely with the International Organization for Standardization (ISO) in accordance with conditions determined by agreement between the two organizations. 2) The
22、formal decisions or agreements of IEC on technical matters express, as nearly as possible, an international consensus of opinion on the relevant subjects since each technical committee has representation from all interested IEC National Committees. 3) IEC Publications have the form of recommendation
23、s for international use and are accepted by IEC National Committees in that sense. While all reasonable efforts are made to ensure that the technical content of IEC Publications is accurate, IEC cannot be held responsible for the way in which they are used or for any misinterpretation by any end use
24、r. 4) In order to promote international uniformity, IEC National Committees undertake to apply IEC Publications transparently to the maximum extent possible in their national and regional publications. Any divergence between any IEC Publication and the corresponding national or regional publication
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSDDIECTS6235182011POWERSYSTEMSMANAGEMENTANDASSOCIATEDINFORMATIONEXCHANGEDATAANDCOMMUNICATIONSSECURITYROLEBASEDACCESSCONTROL

链接地址:http://www.mydoc123.com/p-548346.html