| 1 |
国务院. 关于构建数据基础制度更好发挥数据要素作用的意见 [Z]. 2022.
|
| 2 |
国务院. 关于加快推进电子证照扩大应用领域和全国互通互认的意见 [Z]. 2022.
|
| 3 |
全国人民代表大会常务委员会. 中华人民共和国数据安全法 [Z]. 2021.
|
| 4 |
全国人民代表大会常务委员会. 中华人民共和国个人信息保护法 [Z]. 2021.
|
| 5 |
上海市人民政府办公厅. 上海市电子证照管理办法 [Z]. 2022.
|
| 6 |
Hardt D. RFC 6749: the OAuth 2.0 authorization framework [EB/OL]. (2012-10)[2026-06-25]. https://www.rfc-editor.org/rfc/rfc6749.
|
| 7 |
Sakimura N, Bradley J, Jones M, et al. OpenID Connect Core 1.0 [EB/OL]. (2014-11-08)[2026-06-25]. https://openid.net/specs/openid-connect-core-1_0.html.
|
| 8 |
Jones M, Bradley J, Sakimura N. JSON Web Token (JWT): RFC 7519 [EB/OL]. (2015-05)[2026-06-25]. https://www.rfc-editor.org/rfc/rfc7519.
|
| 9 |
Rose S, Borchert O, Mitchell S, et al. Zero trust architecture: NIST SP 800-207 [R/OL]. (2020-08)[2026-06-25]. https://doi.org/10.6028/NIST.SP.800-207.
|
| 10 |
Ferraiolo D F, Kuhn D R. Role-based access controls [C]//15th National Computer Security Conference. 1992: 554-563.
|
| 11 |
Sandhu R S, Coyne E J, Feinstein H L, et al.. Role-based access control models. Computer, 1996, 29 (2): 38- 47.
|
| 12 |
Hu V C, Ferraiolo D F, Kuhn R, et al. Guide to attribute based access control (ABAC) definition and considerations: NIST SP 800-162 [R]. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2014.
|
| 13 |
OASIS. eXtensible access control markup language (XACML) version 3.0 [EB/OL]. (2013-01-22)[2026-06-25]. https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html.
|
| 14 |
Salehi S A, Han R C, Rudolph C, et al.. DACP: enforcing a dynamic access control policy in cross-domain environments. Computer Networks, 2023, 237, 110049.
|
| 15 |
Tsai M, Lee S, Shieh S W.. Strategy for implementing of zero trust architecture. IEEE Transactions on Reliability, 2024, 73 (1): 93- 100.
|
| 16 |
Denis N, Laurent M, Chabridon S.. A decentralized model for usage and information flow control in distributed systems. Computers & Security, 2024, 144, 103975.
|
| 17 |
U-ruekolan S, Rattananen M, Ponharn J, et al.. Enforcing data access control and privacy: the graph-driven data regulatory approach. Journal of Information Security and Applications, 2025, 93, 104163.
|
| 18 |
Jussen I, Möller F, Schweihoff J, et al.. Issues in inter-organizational data sharing: findings from practice and research challenges. Data & Knowledge Engineering, 2024, 150, 102280.
|
| 19 |
GB/T 35273—2020 信息安全技术 个人信息安全规范 [S].
|
| 20 |
GB/T 36901—2018 电子证照 总体技术架构 [S].
|
| 21 |
GB/T 36906—2018 电子证照 共享服务接口规范 [S].
|
| 22 |
全国人民代表大会常务委员会. 中华人民共和国电子签名法 [Z]. 2019.
|
| 23 |
Zhang Q H, Yuan L Y, Xie T Y, et al.. Auditable and dynamic access control scheme with behavior and identity tracing. Computer Networks, 2024, 251, 110623.
|
| 24 |
Ou Z S, Xing X F, He S Q, et al.. TDS-NA: blockchain-based trusted data sharing scheme with PKI authentication. Computer Communications, 2024, 218, 240- 252.
|
| 25 |
Wang Q, Liu Y.. Blockchain empowered dynamic access control for secure data sharing in collaborative emergency management. Information Processing & Management, 2025, 62 (3): 103960.
|