摘要
将权限定义为由访问类型、信息对象、操作范畴和约束条件构成的四元组,并在此基础上建立包含权限编码生成器、权限编码分析器和权限编码库的基于权限四元组的权限控制模型4-TPBAC(4-Tup le Privilege Based Access Con-trol)。介绍了模型中权限编码生成器和权限编码分析器的工作原理,分析了权限编码分析器中实现页面级权限控制、操作级权限控制和字段级权限控制等控制策略。
The privilege is formally defined as 4 - tuple consists of operation type, information object type, operation scope and eonstralned condition, which is the basis to establish 4 -TPBAC(4 -Tuple Privilege Based Access Control). The 4 -TPBAC model is made up of privilege code builder, privilege code analyst and privilege code base. The working principles of privilege code builder and privilege code analyst in the model are described. Then the strategies of privilege control at level of page, operation and fields in privilege code analyst are expatiated.
出处
《计算机与数字工程》
2006年第10期68-71,共4页
Computer & Digital Engineering