期刊文献+

扩展的基于角色的访问控制模型 被引量:3

Extended role-based access control model
下载PDF
导出
摘要 提出了一种扩展的基于角色的访问控制RBAC (RoleBasedAccessControl)模型———RTBAC (Role&TaskBasedAccessControl)模型 .该模型在RBAC96模型之上引入了任务和任务实例的概念 ,形式化地定义了任务和任务实例的层次结构 ,界定了传统会话同任务实例之间的关系以及任务实例同权限之间的关系 ,并且提供了几种辅助函数 .该模型可以更为自然地描述业务流程和访问控制策略 ,更适合分布式协作应用 ,特别是工作流和组合服务 .基于该模型定义了一种新的动态职责分离约束———基于任务的动态职责分离约束 ,并且同传统动态职责分离约束进行了比较 .该约束可以更准确地刻画访问控制相关的系统运行时上下文的范围 。 An extended RBAC (role based access control) model, RTBAC (role and task based access control) model was presented. The model introduced the notions of task and task instance into RBAC96 model, formally defined the hierarchies of tasks and task instances, specified the relationships between traditional sessions and task instances as well as the relationships between task instances and permissions. Several assistant functions were defined. The model could be used to depict daily business procedures and related access control policies more naturally, so it was more suitable for distributed collaborative applications, especially for workflows and service compositions. Based on this model, a new dynamic separation of duty constraint, namely task-based dynamic separation of duty constraint, was formally defined and compared with traditional dynamic separation of duty constraints using a typical example. The new constraint can specify access control related system runtime context more accurately. It can increase the efficiency of access control at runtime.
作者 薛伟 怀进鹏
出处 《北京航空航天大学学报》 EI CAS CSCD 北大核心 2005年第3期298-302,共5页 Journal of Beijing University of Aeronautics and Astronautics
基金 国家 8 6 3计划基金资助项目 (2 0 0 2AA1 1 30 30 2 0 0 3AA1 44 1 5 0 ) 国家自然科学基金资助项目 (90 41 2 0 1 1 )
关键词 访问控制模型 基于角色的访问控制 运行时上下文 动态职责分离 Applications Composition Constraint theory Control Dynamics Functions Mathematical models
  • 相关文献

参考文献9

  • 1Simon R T, Zurko M E. Separation of duty in role-based environments[A]. In: Proceedings of Computer Security Foundations Workshop X [C]. Washington: IEEE Computer Society, 1997.183~194.
  • 2Gligor V D, Gavrila S I, Ferraiolo D F. On the formal definition of separation-of-duty policies and their composition[A]. In: Proceedings of 1998 Symposium on Research in Security and Privacy [C]. Washington: IEEE Computer Society, 1998.172~185.
  • 3Crampton J. Specifying and enforcing constraints in role-based access control[A]. In: Proceedings of ACM Symposium on Access Control Models and Technologies[C]. New York: ACM Press, 2003.43~50.
  • 4Ahn G J, Sandhu R. Role-based authorization constraints specification[J]. ACM Transactions on Information and System Security, 2000,3(4):207~226.
  • 5Sandhu R, Conyne E J, Lfeinstein H, et al. Role based access control models[J]. IEEE Computer, 1996,29(2):38~47.
  • 6Ferraiolo D F, Sandhu R, Gavrila S, et al. Proposed NIST standard for role-based access control[J]. ACM Transactions on Information and System Security, 2001,4(3):224~274.
  • 7Thomas R K, Sandhu R. Task-based authorization controls (TBAC): models for active and enterprise-oriented authorization management[A]. In: Proceedings of the IFIP TC11 WG11.3 Eleventh International Conference on Database Securty XI: Status and Prospects[C]. London: Chapman&Hall, 1998.262~275.
  • 8Thomas R K, Sandhu R. Task-based authorization: a research project in next-generation active security models for workflows[EB/OL]. http://lsdis.cs.uga.edu/ activities/NSF-workflow/roshan.html, 1996-4-16/2003-6-20.
  • 9Thomas R K. Team-based access control (TMAC): a primitive for applying role-based access controls in collaborative environments[A]. In: Proceedings of the Second ACM workshop on Role-based Access Control[C]. New York: ACM Press, 1997.13~19.

同被引文献12

引证文献3

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部