摘要
在RBAC中,用户拥有权限就可进行相应的访问,没有授权给用户的权限被隐含禁止了。为了防止被隐含禁止的权限将来授权给用户,增强RBAC的安全性,引入显式的负授权是有必要的。本文在RBAC模型基础上,分别在用户分配和权限分配中引入了负授权,讨论了负授权的实现方式及其特点。
In RBAC, the user is allowed to access if he has a corresponding permission,while pennissious which are not authorized to the user imply to be forbidden. To prevent these implied forbidden permissions from being authorized to the user later and to reinforce RBAC' s security, it is necessary to introduce explicit negative authorization in RBAC. Based on RBAC model, this paper introduces negative authorization into the user assignment and permission assignment, and discusses their realizing approaches and features.
出处
《石河子大学学报(自然科学版)》
CAS
2005年第5期654-657,共4页
Journal of Shihezi University(Natural Science)