作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (7): 140-142,168.

• 安全技术 • 上一篇    下一篇

一种改进的基于角色的访问控制

甘 泉 1,2,贺也平1,韩乃平2   

  1. 1. 中国科学院软件研究所信息安全工程研究中心,北京 100080;2. 上海中标软件有限公司,北京 100081
  • 出版日期:2006-04-05 发布日期:2006-04-05

An Improved Role Based Access Control

GAN Quan1,2, HE Yeping1, HAN Naiping2   

  1. 1. Engineering and Research Center for Information Security Technology, Institute of Software, Chinese Academy of Sciences, Beijing 100080;2. China Standard Software Co., Ltd., Beijing 100081
  • Online:2006-04-05 Published:2006-04-05

摘要: 研究了传统RBAC(基于角色的访问控制)的4 个层次模型,分析了在企业规模不断扩大背景下传统RBAC 的不足,并借鉴DTE模型域和型的思想,提出了通过引入主体和客体的属性(区域)参数以及虚拟权限的解决方法,极大地减少了角色的规模,降低了角色管理的复杂性,为进一步解决角色冲突等问题奠定了基础。

关键词: 访问控制;基于角色的访问控制;区域

Abstract: This paper introduces the basic concept of RBAC by the exemplification of four level models, then analyzes the shortcomings of traditional RBAC in the background of gradual enlargement of scale of the enterprise. Finally it refers the idea of domain and type of the DTE model and shows a way to solve it by introducing the parameter of subject’s attribute and object’s attribute. This way can reduce the number of the role and the complexity of role's management and it can establish the foundation for further solving such problems as the role conflict

Key words: Access control; Role based access control(RBAC); Domain