节点文献

基于角色的访问控制模型的扩充和实现机制研究

Research on Extension and Implementation Mechanism for Role-Based Access Control

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 薛伟怀进鹏

【Author】 XUE Wei and HUAI Jin-Peng( School of Computer Science & Engineering, Beijing University of Aeronautics and Astronautics, Beijing 100083)

【机构】 北京航空航天大学计算机学院北京航空航天大学计算机学院 北京 100083北京 100083

【摘要】 同传统的自由访问控制(DAC)和强制访问控制(MAC)相比,基于角色的访问控制(RBAC)代表了在灵活性和控制粒度上的一个重大进步.为了促进RBAC的研究和应用,美国国家技术与标准局提出了RBAC建议标准.然而,该标准仅支持一种约束,即职责分离约束.提出了一个经过扩展的RBAC标准——e-RBAC,增加了对广泛使用的势约束的直接支持.提出了一个面向对象的RBAC系统实现框架,该框架可部分起到API标准的作用.在此框架之下实现了一个通用的RBAC核心功能模块act-RBAC.

【Abstract】 Role-based access control (RBAC) represents an important advancement in flexibility and granularity of control from the classical discretionary and mandatory access control. To accelerate the research and application of RBAC, NIST in USA has proposed a standard for it. But the standard supports only one constraint type, namely separation of duty. An extended RBAC standard that directly supports the widely used cardinality constraint, e-RBAC, is proposed. An object-oriented implementation framework for RBAC system is proposed and can be used as an API standard. A general core functional module for RBAC systems is implemented with respect to the proposed framework.

【基金】 国家“八六三”高技术研究发展计划项目(2001AA110485,2001AA10233,2001AA144150);国家自然科学基金(60073006)
  • 【文献出处】 计算机研究与发展 ,Journal of Computer Research and Development , 编辑部邮箱 ,2003年11期
  • 【分类号】TP393.08
  • 【被引频次】74
  • 【下载频次】403
节点文献中: 

本文链接的文献网络图示:

本文的引文网络