作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (16): 138-141. doi: 10.3969/j.issn.1000-3428.2012.16.035

• 安全技术 • 上一篇    下一篇

一种基于T-RBAC的访问控制改进模型

冯 俊,王 箭   

  1. (南京航空航天大学计算机科学与技术学院,南京 210016)
  • 收稿日期:2011-11-03 修回日期:2011-12-08 出版日期:2012-08-20 发布日期:2012-08-17
  • 作者简介:冯 俊(1986-),男,硕士研究生,主研方向:访问控制技术;王 箭,教授、博士、博士生导师
  • 基金资助:

    国家“863”计划基金资助项目(2009AA044601)

Improved Access Control Model Based on T-RBAC

FENG Jun, WAGN Jian   

  1. (College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 210016, China)
  • Received:2011-11-03 Revised:2011-12-08 Online:2012-08-20 Published:2012-08-17

摘要: 针对T-RBAC在权限控制及职责分离上存在的不足,提出一种改进模型。新模型简化T-RBAC模型的任务分类,为任务加入任务上下文及任务状态属性,使权限的授予与任务上下文、任务状态紧密联系,增强对权限的动态管理。利用私有角色解决互斥权限在继承过程中可能产生的权限共享问题。使用历史记录保证任务执行过程中的动态职责分离。该模型提供了更细粒度的权限管理,能更好地满足职责分离和最小特权原则。

关键词: 任务上下文, 任务状态, 权限动态管理, 职责分离, 互斥权限共享

Abstract: Because of the shortcoming of permission control and separation of duties in T-RBAC, an improved model is proposed. New model simplifies the task classification of T-RBAC, adds context and state property to task, and builds a close relationship between permissions granting and the task context and state property, which enhances the dynamic management of permissions. It also solves the problem of mutually exclusive rights possessed by one role while inherited in roles hierarchy using private roles, and ensures the dynamic separation of duties by checking the history of task performance. New model provides a better permissions management, and better meets the separation of duties and least privilege principles.

Key words: task context, task state, dynamic management of permission, separation of duties, mutually rights sharing

中图分类号: