摘要
目前RBAC模型已得到广泛的认同,但传统的RBAC实现脱离了企业的组织架构,同时认证模块与应用程序紧耦合也可给系统的维护和实现带来困难。该文在大量研究已实现RBAC模型的基础上提出了基于Principal的认证与授权模型、算法的大致思想,并提供了基于J2EE的实现方案。
Current RBAC models have gained general recognition, but the realization of traditional RBAC is divorced from the organizational structure of enterprises, and the tight coincidence of authentication modules and applications causes troubles to maintenance and realization of the system. A principal-based authentication, authorization model and algorithm are introduced and they are based on the realized RBAC models, as well as a J2EE-based realization is presented.
出处
《计算机工程》
EI
CAS
CSCD
北大核心
2005年第9期67-69,215,共4页
Computer Engineering
基金
国家"863"计划基金资助项目(2001AA415220)
关键词
访问控制
企业级
责任人
JAAS
J2EE
Access control
Enterprise
Principal
Java authentication and authorization service (JAAS)
J2EE