作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (05): 120-122. doi: 10.3969/j.issn.1000-3428.2007.05.042

• 安全技术 • 上一篇    下一篇

角色管理自动化的访问控制

李 佳1,徐向阳2   

  1. (1. 湖南大学校长办公室,长沙 410082;2. 湖南大学计算机与通信学院,长沙 410082)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-03-05 发布日期:2007-03-05

Role Auto-assignment for Access Control

LI Jia1, XU Xiangyang2   

  1. (1. School Master Office, Hunan University, Changsha 410082; 2. School of Computer and Communication, Hunan University, Changsha 410082)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-03-05 Published:2007-03-05

摘要: 基于角色的访问控制是简化企业信息系统访问控制的一个有效策略。近年来规则已经被用于支持用户角色的自动管理。该文引入职能控制集的概念,结合角色和规则的优点,提出了一种新的适合于大型企业的安全访问控制方案,实现角色分解和权限细粒度控制的目的,根据企业的安全管理策略和用户的属性,自动管理用户-角色的分配,还引入否定授权策略,增强了客体权限分配的灵活性和安全性。

关键词: 访问控制, 角色, 规则, 职能控制集

Abstract: Role-based access control (RBAC) is a useful policy for simplifying access control on enterprise information system. Recently, rule concept is used to support role assignment automatically. By introducing the concept of function control sets and combining the virtue of role and rule, this paper proposes a new security access control scheme suitable for large organizations, which can enhance the flexibility and security on object permission assignment, assign role for user automatically based on user attributes.

Key words: Access control, Role, Rule, Function control sets