作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (13): 137-139. doi: 10.3969/j.issn.1000-3428.2010.13.048

• 安全技术 • 上一篇    下一篇

基于模糊的RBAC模型研究与优化

王宇新,田 佳,郭 禾,王 政,杨元生   

  1. (大连理工大学电子与信息工程学院,大连 116024)
  • 出版日期:2010-07-05 发布日期:2010-07-05
  • 作者简介:王宇新(1973-),男,讲师、硕士,主研方向:软件工程,计算机系统结构;田 佳,硕士研究生;郭 禾,教授、博士生导师;王 政,硕士研究生;杨元生,教授、博士生导师

Research and Optimization of Fuzzy-based RBAC Model

WANG Yu-xin, TIAN Jia, GUO He, WANG Zheng, YANG Yuan-sheng   

  1. (School of Electronic and Information Engineering, Dalian University of Technology, Dalian 116024)
  • Online:2010-07-05 Published:2010-07-05

摘要: 传统的RBAC策略在企业用户数量剧增时,角色指派和权限维护成为系统管理员沉重的负担。为简化管理员的工作、规范安全策略,提出一种基于模糊的RBAC优化模型。使用位图矩阵进行角色信任度计算。将方差引入因素权重向量的调整策略,改进取大取小操作的局限性。对相似的用户聚类,在聚类中分享群体经验提高模型的精确性。为用户引入历史互斥权限表,实现带有责任分离约束的模糊RBAC模型。

关键词: 模糊, 基于角色的访问控制, 聚类分析, 责任分离

Abstract: With the rapid increase of the enterprise users, it is a tiresome task for the system administrator to assign roles and maintain permissions in traditional Role-Based Access Control(RBAC) strategy. In order to simplify the administrator’s work and standardize security strategy, an optimized RBAC model based on fuzzy is proposed. Bitmap matrix is used for computing role’s trustworthiness. Variance is applied to adjust attribute weight vector to improve max-min operation’s limitation. By clustering similar users, group experience is shared among the users within the same cluster to improve the accuracy of the model. A fuzzy RBAC model with separation of duty constraint is implemented by enforcing a historical, mutual exclusive permission table for each user.

Key words: fuzzy, Role-Based Access Control(RBAC), clustering analysis, separation of duty

中图分类号: