
基于Web的图书馆管理系统访问控制策略 被引量:4

Access Control Policies for Web Based Library Management System
摘要 针对基于Web的图书馆管理系统资源访问控制的动态性问题,提出了一种基于角色的访问控制策略描述方案.通过对基于Web的图书馆管理系统访问控制管理影响因素和访问控制需求的分析,结合NIST基于角色的访问控制统一模型标准,构造了一种基于角色的访问控制元模型.并在这一元模型的基础上,提出了一种紧凑的基于角色的访问控制XML策略描述语言框架.结果表明该访问控制策略描述语言框架适合表述动态环境下对图书馆资源的访问策略,提高了基于Web的图书馆管理系统资源访问的安全性. This paper proposes a specification of Role Based Access Control policies to solve the dynamic access control for the Web based library management system. According to the NIST unified Role Based Control model standards, a Role Based Access Control meta-model is constructed based on the analysis of the affecting factors of the access control management and the access control requirements for the Web based library management system. Based on this meta-model, a compact Role Based Access Control XML policy specification language framework is proposed. The results show that this policy specification language framework can represent the access policies for library materials in dynamic environment, and improve the security to access the materials in the Web based library management system.
出处 《武汉大学学报(理学版)》 CAS CSCD 北大核心 2006年第5期644-648,共5页 Journal of Wuhan University:Natural Science Edition
基金 教育部博士点基金资助项目(20030533011)
关键词 基于Web的图书馆管理系统 基于角色的访问控制 访问控制策略描述 Web based library management system role based access control access control policy specification
  • 相关文献


  • 1Park J,Sandhu R, Ahn G. Role Based Access Controlon the Web [J]. ACM Transactions on Information and System Security, 2001,4(1) :37-71.
  • 2Sandhu R,Ferraiolo D, Kuhn R. The NIST Model for Role-based Access Control Towards a Unified Standard[C]//Proceedings of the 5th ACM Workshop on Role Based Access Control. Berlin: ACM Press, 2000:47-63.
  • 3Bhatti R, Joshi J, Bertino E, et al. Access Control in Dynamic XML-Based Web-Services with X-RBAC[C]//Proceedings of the First International Conference on Web Services. Las Vegas: CSREA Press,2003:23-26.
  • 4Hartman B, Flinn D, Beznosov K, et al. Mastering Web Services Security [M]. Indianapolis: John Wiley & Sons, 2003.
  • 5Ferraiolo D, Sandhu R, Gavrila S, et al. Proposed NIST Standard for Role Based Access Control [J].ACM Transactions on Information and System Security ,2001,4(3) :224-274.
  • 6Nguyen D. A Study on Role-Based Access Control[D]. Florida: the Graduate School of the University of Florida, 2001.
  • 7W3C. Extensible Markup Language [EB/OL]. [2006-01-22]. http://www.w3. org/xml/.
  • 8W3C. XML Schema Part0: Primer Second Edition[EB/OL]. [2005-01-28]. http://www. w3. org/TR/xmlschema- 0/.
  • 9Bertino E,Castano S,Ferrari E. On Specifying Security Policies for Web Documents with an XML Based Language [C]//Proceedings of the 6th ACM Symposium on Access Control Models and Technologies.Chantilly: ACM Press,2001:57-65.
  • 10Bertino E,Castano S, Ferrari E. Securing XML Documents with Author X[J]. IEEE Internet Computing,2001,5(3) :21-31.











使用帮助 返回顶部