作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (8): 19-21. doi: 10.3969/j.issn.1000-3428.2008.08.007

• 博士论文 • 上一篇    下一篇

基于XACML的访问控制与RBAC限制

努尔买买提•黑力力1,2,罗振兴1,林作铨1   

  1. (1. 北京大学信息科学系,北京 100871;2. 新疆大学数学与系统科学学院,乌鲁木齐 830046)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-04-20 发布日期:2008-04-20

XACML-based Access Control and RBAC Constraints

Nuermaimaiti•Heilili1,2, LUO Zhen-xing1, LIN Zuo-quan1   

  1. (1. Department of Information Science, Peking University, Beijing 100871; 2. College of Mathematics and System Sciences, Xinjiang University, Urumqi 830046)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-04-20 Published:2008-04-20

摘要: 限制可以视为是基于角色的访问控制(RBAC)的主要动机。该文分析基于XML的访问控制规范语言(XACML)的RBAC框架并指出了该框架的缺点,通过提出的角色激活机构对该框架进行扩充,使得XACML支持RBAC模型中的职责分离和基数限制等限制。

关键词: Web服务, XML的访问控制规范语言, 基于角色的访问控制

Abstract:

Constraints are considered to be the principal motivation for Role-Based Access Control(RBAC). This paper analyzes XML based access control language XACML and points out some shortcomings of the XACML profile for RBAC. It provides role enablement authority to extend this profile, in this way, several kinds of constraints of RBAC such as separation of duty constraints and cardinality constraints can be enforced and implemented using XACML.

Key words: Web services, eXtensible Access Control Markup Language(XACML), Role-Based Access Control(RBAC)

中图分类号: