节点文献

Web服务基于代理和角色的访问控制模型研究

A Role-and Agent-Based Access Control Model in Web Services

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 李庆华王小兵王多强

【Author】 LI Qing-hua,WANG Xiao-bing,WANG Duo-qiang (School of Computer Science and Technology,Huazhong University of Science and Technology,Wuhan 430074,China)

【机构】 华中科技大学计算机科学与技术学院华中科技大学计算机科学与技术学院 湖北武汉430074湖北武汉430074

【摘要】 在Web服务中,由于传统的基于角色的访问控制模型(RBAC)无法灵活地实现基于内容和上下文的访问控制策略,从而无法适应Web服务代理动态、临时性的特点,也不能满足Web服务内容和上下文敏感的要求。因此,本文提出了一种基于代理和角色的访问控制模型(ARBAC)。本模型中,Web服务代理访问控制器根据用户及代理权限生成代理实体来取代用户访问主体的角色。代理实体是用户授权的临时的虚拟实体,它的权限是由用户和代理两者的访问权限决定的。理论上,它的生命周期是在一次访问请求范围内。

【Abstract】 In Web services, the traditional role-based access control model cannot implement content-based and context-based access control policies flexibly.It cannot meet the demands of Web Services agent’s dynamic and temporary features and Web services’ context and content sensitivity.We propose a role-and agent-based access control model (ARBAC).In the ARBAC model, the access controller of the Web services’ agent will produce an agent entity which is used to replace the user(subject). The agent entity is a temporary and fictitious subject whose permission is limited by the permission of the user and whose life cycle is within one requisition.

【关键词】 Web服务代理代理实体RBACARBAC
【Key words】 Web servicesagentagent entityRBACARBAC
  • 【文献出处】 计算机工程与科学 ,Computer Engineering & Science , 编辑部邮箱 ,2006年12期
  • 【分类号】TP393.08
  • 【被引频次】5
  • 【下载频次】112
节点文献中: 

本文链接的文献网络图示:

本文的引文网络