作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (10): 155-157. doi: 10.3969/j.issn.1000-3428.2009.10.051

• 安全技术 • 上一篇    下一篇

面向组织结构的访问控制模型

赵小龙1,张毓森1,袁 峰2   

  1. (1. 解放军理工大学指挥自动化学院,南京 210007;2. 国家信息安全工程技术研究中心,北京 100093)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-05-20 发布日期:2009-05-20

Organization-Structure Oriented Access Control Model

ZHAO Xiao-long1, ZHANG Yu-sen1, YUAN Feng2   

  1. (1. School of Command Automation, PLA University of Science and Technology, Nanjing 210007;2. National Information Security Engineering Technology Research Center, Beijing 100093)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-05-20 Published:2009-05-20

摘要: 引入组织域的概念,描述企业组织的层状结构,在此基础上重新定义访问控制要素,提出面向组织结构的访问控制(OSOAC)模型,并扩展得到等级OSOAC模型和约束OSOAC模型。与RBAC模型相比,OSOAC模型能减少角色数量和权限分配关系,降低大型访问控制系统的管理复杂度。

关键词: 访问控制, 组织域, 角色, 等级, 约束

Abstract: The concept of organization domain is introduced to describe the hierarchical structure of the enterprise organization. Based on the concept, the elements of access control are redefined and an Organization-Structure Oriented Access Control(OSOAC) model is proposed. The hierarchical OSOAC model and constrained OSOAC model are drawn by extended the Core OSOAC model. Contrast to RBAC model, there are fewer roles and permission assignment relations in OSOAC model, which reduce the privilege-management complexity in a large access control system.

Key words: access control, organization domain, role, hierarchy, constraint

中图分类号: