期刊文献+

具有负授权的角色访问控制

Role-based Access Control with Negative Authorization
下载PDF
导出
摘要 在RBAC中,用户拥有权限就可进行相应的访问,没有授权给用户的权限被隐含禁止了。为了防止被隐含禁止的权限将来授权给用户,增强RBAC的安全性,引入显式的负授权是有必要的。本文在RBAC模型基础上,分别在用户分配和权限分配中引入了负授权,讨论了负授权的实现方式及其特点。 In RBAC, the user is allowed to access if he has a corresponding permission,while pennissious which are not authorized to the user imply to be forbidden. To prevent these implied forbidden permissions from being authorized to the user later and to reinforce RBAC' s security, it is necessary to introduce explicit negative authorization in RBAC. Based on RBAC model, this paper introduces negative authorization into the user assignment and permission assignment, and discusses their realizing approaches and features.
作者 徐燕 彭军
出处 《石河子大学学报(自然科学版)》 CAS 2005年第5期654-657,共4页 Journal of Shihezi University(Natural Science)
关键词 基于角色的访问控制 负授权 用户分配 权限分配 RBAC negative authorization user assignment permission assignment
  • 相关文献

参考文献6

  • 1S Jajodia,P Samarati.Flexible support for multiple access control policies[J].ACM Transactions on Database Systems,2001,26(2):214-260.
  • 2Ravi S Sandhu,Edward J Coyne,et al.Role-based access control models[J].IEEE Computer,1996,29(2):38-47.
  • 3Ravi S Sandhu,Ferraiolo David,et al.The NIST model for role-base access control:toward a unified standard[A].Proceedings,Fifth ACM Workshop on Role-based Access Control[C],New York:ACM Press,2000,47-63.
  • 4Ferraiolo D F,Sandhu R.Proposed NIST standard for role-based access control[J].ACM Transactions on Information and System Security,2001,4(3):224-274.
  • 5R Sandhu,V Bhamidipati,et al.The ARBAC97 model for role-based administration of roles[J].ACM Transactions on Information and System Security,1999,2(1):105-135.
  • 6S Osborn,R Sandhu,et al.Configuring role-based access control to enforce mandatory and discretionary access control policies[J].ACM Transactions on Information and System Security,2000,3(2):85-106.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部