节点文献
结合属性和角色的Web服务访问控制
Access control for web services combining attributes with roles
【摘要】 在分析Web服务访问控制需求的基础上,指出了现有访问控制模型在Web服务访问控制方面的局限性,提出了一种结合属性和角色的Web服务访问控制模型ARBAC,给出了软件实现结构。ARBAC模型给出了Web服务访问控制领域中的概念定义,提出了相关判定定理。ARBAC模型根据Web服务资源对用户的属性限制条件自动生成角色集,完成用户到角色、权限到角色的映射,能够表达职责分离约束、环境参数限制和最小权限策略,统一了Web服务和服务所涉及的数据资源的访问控制。
【Abstract】 Based on the analysis of the access control requirements for web services,the limitation of current access control models for web services is pointed out,and a combining attributes with roles access control(ARBAC) model for web services and the architecture of the implementation is presented.The ARBAC model defines concepts of the access control for web services,and gives several judgment theorems.The ARBAC model could automatically produce the role set according to limitation requirements for users’ attributes,accomplish the mapping among users,permissions and roles,and unify the access control for web services and data resources involved.
【Key words】 information security; access control; web service; role; authorization;
- 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2012年02期
- 【分类号】TP393.08
- 【被引频次】7
- 【下载频次】159