期刊文献+

基于任务和角色的双重Web访问控制模型 被引量:18

A Task and Role-Based Access Control Model for Web
下载PDF
导出
摘要 互联网 /内联网和相关技术的迅速发展为开发和使用基于Web的大规模分布式应用提供了前所未有的机遇 ,企业级用户对基于Web的应用 (Web basedapplication ,WBA)依赖程度越来越高 访问控制作为一种实现信息安全的有效措施 ,在WBA的安全中起着重要作用 但目前用来实现WBA安全的访问控制技术大多是基于单个用户管理的 ,不能很好地适应企业级用户的安全需求 因此提出了基于任务和角色的双重Web访问控制模型 (taskandrole basedaccesscontrolmodelforWeb ,TRBAC) ,它能够满足大规模应用环境的Web访问控制需求 并对如何在Web上实现TRBAC模型进行了探讨 ,提供了建议 同时 。 The rapid proliferation of the Internet/Intranet and the cost effective growth of its key enabling technologies are creating unprecedented opportunities for developing large scale Web based distributed applications It has led to continued reliance on Web based applications (WBA) for enterprise wide computing At the same time, there is a growing concern over the security of WBA As an effective measure to achieve information security, access control is important in WBA security However, current approaches to access control on WBA are mostly based on individual user identity; hence they do not scale to enterprise wide systems In this paper, a new access control mechanism called TRBAC(task and role based access control model for Web,TRBAC) is presented The TRBAC model can meet the need to manage and enforce the strong and efficient access control technology in large scale Web environments The implementation of TRBAC on the Web is also illustrated Finally, the Web application adopting the TRBAC model, called E Government Official Document Flow & Processing System, is given to demonstrate the feasibility
出处 《计算机研究与发展》 EI CSCD 北大核心 2004年第9期1466-1473,共8页 Journal of Computer Research and Development
基金 国家"八六三"高技术研究发展计划基金项目(2 0 0 1AA14 40 10 ) 江苏省科技攻关基金项目 (BG2 0 0 0 0 0 6)
关键词 角色 基于任务的访问控制 任务 WEB安全 安全cookies role task-based access control task Web security secure cookies
  • 相关文献

参考文献7

  • 1Rohit Khare. Web Security: A Matter of Trust. Sebastopol: O'Reilly & Associates Inc, 1997
  • 2Ferraiolo D, Kuhn R. Role-based access controls. In: Proc of the 15th NIST-NCSC National Computer Security Conference. Garthersburg, MD: National Institute of Standards and Technology, 1992. 554~563
  • 3Sandhu R, Conyne EJ, Lfeinstein H, et al. Role based access control models. IEEE Computer, 1996, 29(2): 38~47
  • 4Park Joon S, Sandhu R, Ahn Gail-Joon. Role-based access control on the Web. ACM Trans on Information and System Security, 2001, 4(1): 37~71
  • 5Thomas R K, Sandhu R. Task-based authentication controls (TABC): A family of models for active and enterprise-oriented authentication management. In: Proc of the IFIP WG11.3 Workshop on Database Security. London: Chapman & Hall, 1997. 166~181
  • 6邓集波,洪帆.基于任务的访问控制模型[J].软件学报,2003,14(1):76-82. 被引量:222
  • 7D kristol, L Montulli. HTTP state management mechanism. RFC 2965, Network Working Group, Internet Engineering Task Force. http://www.ietf.org/rfc/rfc2965.txt, 2000

二级参考文献1

共引文献221

同被引文献136

引证文献18

二级引证文献54

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部