节点文献

基于Eclipse插件技术的RBAC模型的研究与实现

The Research and Implementation of RBAC Model Based on Eclipse Plug-in Technology

【作者】 张晓群

【导师】 董丽丽;

【作者基本信息】 西安建筑科技大学 , 计算机应用技术, 2007, 硕士

【摘要】 访问控制作为国际化标准组织定义的五项标准安全服务之一,是实现信息系统安全的一项重要机制。作为访问控制技术之一的基于角色的访问控制(RBAC)已在很多企事业单位的信息系统中显示出极大的优势。然而,RBAC模型中访问控制策略的实施完全依靠管理员操作来完成,这虽然适合角色数量少的应用系统,但当应用系统中角色数量增大时,一方面会导致管理员的工作量增大,另一方面又使得系统访问控制策略实施存在一定的随意性,难以保障访问控制策略实施的正确性。本文重点对角色访问控制模型中角色-权限分配进行研究,分析如何运用角色的属性将角色分配到相应权限的合理化途径,以解决角色-权限分配对管理员的依赖问题,从而保障访问策略实施的正确性。由于基于角色访问控制技术已在大型信息系统中得到广泛应用。本文研究的另一问题是开发一个通用的扩展RBAC插件,使得它能与不同的应用系统进行无缝集成,完成应用系统的访问权限控制功能,以缩短应用系统的开发周期。文中首先研究了基于角色的访问控制模型,分析了该模型在大型应用系统中实施访问控制策略时,由系统管理员进行角色-权限分配所存在的弊端。其次,针对该弊端对角色访问控制模型进行以下改进:定义角色的职责范围,提取角色的属性、按属性对角色进行逐步分解,以产生角色对应的权限。再次,对Eclipse平台进行研究,详细分析了Eclipse插件的工作机制及开发方法。最后,应用Eclipse插件开发环境PDE设计并实现了通用的扩展RBAC插件。

【Abstract】 As the one of the five standard security services established by International Standard Organization (ISO), Access Control (AC) is an important mechanism of Information Security (IS). Role-based Access Control (RBAC) is one kind of the AC technology, which has many advantages for applications in many enterprises recently. Because access control policy based on RBAC model is implemented by system administrator, this technique is only appropriate in application system that has a small quantity of roles and it can increase the system administrators’ workload and induce access control policy discretional for the application system that has large numbers of roles. So it doesn’t ensure the implementation of access control policy correctly.In this paper, an assignment method of role-permission in RBAC has been researched. The rationalized approach that assigns roles to the corresponding permissions according to the property of role is analyzed. As a result, the problem in which the role-permission assignment relies on administrator is solved by this means. Consequently, the correctness of the implementation of access control policy can be ensured. With the application of RBAC technology broadly in large information systems, how to realize a universal extended RBAC plug-in and make it integrate with different applications to accomplish the access control function of application system and shorten cycle of development application system is another important research problem in this paper.Firstly, the RBAC model is researched in this paper. And the shortage of the RBAC model in application is analyzed. Secondly, the RBAC model is improved, such as defining the function range of role, picking-up the property of role, decomposing roles according to property. And then the permission corresponding to role is produced. Thirdly, Eclipse platform is researched. The eclipse principle and the plug-in development method are analyzed detailedly. Finally, universal extended RBAC plug-in is designed and realized in Plug-in Development Environment(PDE) of Eclipse.

【关键词】 RBAC角色-权限分配OSGIEclipse插件
【Key words】 RBACRole-Permission assignmentOSGIEclipsePlug-in
  • 【分类号】TP311.52
  • 【被引频次】5
  • 【下载频次】264
节点文献中: 

本文链接的文献网络图示:

本文的引文网络