摘要
基于Web的管理信息系统的安全问题从数据的访问控制和Web的访问控制两方面设计.数据访问控制,采用基于角色的访问控制(RBAC,RoleBasedAccessControl)的安全策略.Web的访问控制,设计为用户的认证与授权,根据用户权限定制网页两部分.
The design of security for Web based MIS should think over two aspects, firstly, the access control of database, next , the access control of Web pages. The access control of database use role based access control (RBAC) model. The access control of Web pages is designed two objects: the users' attestation and authorization, and making Web pages according to users' power.
出处
《河北工业大学学报》
CAS
2004年第3期45-49,共5页
Journal of Hebei University of Technology
关键词
基于角色
访问控制
授权
认证
based role
access control
authorization
attestation