摘要
分析了目前几种主要RBAC模型中系统管理员权限缺乏约束的问题.提出了一种对超级用户权限的控制方法,通过引入安全员与审计员两个角色,使超级用户之间的权限相互制约,改善了在创建角色及用户授权方面的安全性,从而进一步增强信息系统的安全性.
Currently, there are some models that extend RBAC model. However, their supports for constraints on the permission of super users are very limited. This paper proposes a new idea for control permission of administrator. By introducing comptroller role and security role, the permission between super users is mutually checked and supervised. This technique can increase the safeness of creating role and user's authorization, then strengthen the safeness of the information system.
出处
《山东理工大学学报(自然科学版)》
CAS
2007年第1期77-80,共4页
Journal of Shandong University of Technology:Natural Science Edition