节点文献
基于规则的RBAC在Web信息系统中的实现
Implementing Rule-Based RBAC in Web Information System
【摘要】 针对Web资源访问的特点和安全问题,研究了传统的RBAC(Role-Based Access Con-trol)模型的缺陷,提出了一种适合大型Web资源访问系统的RBAC扩展模型,即利用用户属性制定相应的规则,根据规则为用户分配角色,以获得相应Web资源的访问权限.该扩展模型弥补了传统RBAC基于静态角色分配的不足,实现了角色的动态分配,并对规则和角色分配进行了约束,提高了Web资源访问的效率和安全性.
【Abstract】 Aiming at characteristics and safe problems of the Web resources access,studies in the deficiency of the traditional RBAC(the Role-Based Access Control) model,puts forward a kind of RBAC patulous model which is fit for the large system of Web resources access.Namely it establishes rules with the users’ attributes,assigning the role for the customer according to the rule.That model makes up for the shortage of the traditional RBAC with static role-assignment,implements the dynamic allotment of the role,and makes constraints on the rule and the role allotment,raising the efficiency and the safety of the Web resources access.
- 【文献出处】 四川大学学报(自然科学版) ,Journal of Sichuan University(Natural Science Edition) , 编辑部邮箱 ,2006年06期
- 【分类号】TP393.08
- 【被引频次】12
- 【下载频次】146