期刊文献+

改进的基于组织结构的RBAC模型 被引量:2

Improved RBAC model based on organization structure
在线阅读 下载PDF
导出
摘要 针对传统的基于角色的访问控制模型在大型应用系统中存在角色数目巨大、临时授权管理繁琐等问题,提出了一种改进的基于组织结构的RBAC模型(IO-RBAC)。该模型规定角色只有在特定的组织部门中才能获取相应的权限,并能通过对特殊用户直接授权的方式实现临时授权。实际应用案例表明,该模型在减少角色数量的同时,提高了权限管理的灵活性。 The traditional RBAC model has some disadvantages in the use of large application system such as the large number of roles, numerous temporary access authorizations, and so on.To resolve these problems, an improved RBAC model, based on organization structure(IO-RBAC) is put forward.In this new model, roles are authorized only in given organizations, and temporary permission is carried out by authorizing to a special user.Application shows that IO-RBAC model not only reduce the number of roles but also improve the flexibility of permission management.
出处 《计算机工程与设计》 CSCD 北大核心 2009年第23期5340-5343,共4页 Computer Engineering and Design
基金 国家自然科学基金项目(60773055) 江西省卫生厅科技计划基金项目(ID20071995)
关键词 基于角色的访问控制 角色 访问控制 组织结构 权限管理 RBAC(role-based access control) role access control organizational structure permission management
  • 相关文献

参考文献8

二级参考文献26

  • 1孙巍,徐学东,徐学军.Java反射机制在可重构Web框架中的应用[J].计算机工程与应用,2005,41(36):92-94. 被引量:11
  • 2张方舟,王东安,李生,秦刚,宋成.采用J2EE安全机制支持RBAC模型的研究和实现[J].计算机工程,2006,32(13):125-127. 被引量:7
  • 3Department of Defence (USA). Department of Defense Trusted Computer system evaluation criteria. DoD 5200-78-STD, DoD,1985
  • 4Sandhu R,Ferraiolo D, Kuhn R. The NIST model for role-based access control: towards a unified standard. In: Proc. of 5th ACM Workshop on Role-Based Access Control, ACM, Berlin, Germany, July, 2000
  • 5Osborn S,Sandhu R,Munawer M. Configuring role-based access control to enforce mandatory and discretionary access control policies. ACM Transactions on Information and System Security,2000,3(2)
  • 6Sandhu R,et al. Role-baseed access control model. IEEE Computer,1996,29(2)
  • 7Sandhu R. Role activation hierarchies. In: Proc. of 3rd ACM Workshop on Role-Based Access Control, ACM, Fairfax, Oct. 1998
  • 8Sandhu R,et al. Role-based access control models. IEEE Computer, 1996,29 (2): 38~47
  • 9Ahn G J,Sandhu R. The RSL99 language for role-based separation od duty constraints. In: proc. of 4th ACM Workshop on RoleBased Access Control, Fairfax, VA ,Oct. 1999.43~ 54
  • 10Sandhu R,Bhamidipati V,Munawer Q. The ARBAC97 model for role-based administration of roles. ACM Transactions on Information and system Security, 1999,2(1 ): 105~ 135

共引文献46

同被引文献10

引证文献2

二级引证文献11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部