节点文献

基于角色的访问控制扩展模型研究与实现

Research and Design of an Extend Model of Role-Based Access Control

【作者】 王芳

【导师】 李辉;

【作者基本信息】 北京化工大学 , 计算机应用技术, 2006, 硕士

【摘要】 随着电子商务和无纸化办公深入到各个领域,基于角色的访问控制方式得到广泛的应用,并形成了NIST RBAC标准。本文在NIST RBAC的基础上提出一种新的扩展模型,扩展模型依据客体和操作的属性特点抽象出客体角色和操作角色概念,增强了RBAC模型的平衡性,并加入任务概念强化NIST RBAC中的最小权限原则。RBAC扩展模型体现了“一切皆角色”的策略理念,一切皆角色,模型只包含对象、角色、角色之间的关系三种内容。相较于NIST RBAC,扩展模型更为灵活、安全、实用性更强。 本论文结合实际应用系统的需求,设计并实现了基于扩展模型理念的权限系统。系统分为四部分:主体部分、客体部分、操作部分和任务部分。在论文各章节中,逐个详细阐述了子模块的功能特点、设计结构,并进一步分析了体现的模型理论。最后,本文给出了该系统的实验结论,对系统的优缺点进行了综合评价。

【Abstract】 Along with E-Commerce and The realization work with no paper at all apply to various industries, Role-Based Access Control was widely used and NIST Role-Based Access Control standard came into being. In this paper, an extended Role-base access control model based on NIST RBAC was proposed. The extended model has some new elements like operation-roles according to abstracts of operation, object-roles according to abstracts of object, task for "the worst privilege" rule. The extended Role-Based Access Control model represents that everything belongs to its roles. Therefore, it just contains entities、 roles、 relations between role and role. Compared with NIST role-based access control model, the extended one is more flexible, more useable, more functional and safer.Combined with real requirement, this paper sets out design and realization of permission system based on the extended model. Permission system comprises four main parts: user part, object part, operation part and task. In latter sections, each subsystem is introduced specifically for its structure and quality, and corresponding model concept is particularly analyzed. At the end of this work, experiment results are

  • 【分类号】TP393.08
  • 【被引频次】9
  • 【下载频次】180
节点文献中: