期刊文献+

P-RBAC:一种门户环境下的访问控制模型 被引量:3

P-RBAC:access control model in portal systems
下载PDF
导出
摘要 门户能够有效地实现异构信息之间的集成与协作,并为用户提供可定制、统一且遵循规范的访问服务。然而,由于门户所具有的这些不同于普通Web应用的特性,也使得传统访问控制模型无法在门户中直接使用。提出了一种面向门户系统的访问控制模型P-RBAC。P-RBAC扩展了传统的基于角色访问控制模型,并根据行为状态进一步分为静态模型和动态模型。P-RBAC给出了静态模型和动态模型上的行为规则,提出了具体的动态权限指派和角色组织策略,从而有效地解决了门户的访问控制问题。实际的应用案例证明,P-RBAC模型能够适用于门户的访问控制,并较之传统访问控制模型更高效可行。 Portals facilitate users to easily access information by integrating heterogeneous applications,services and data resources in a consistent way However,traditional access control models are not applicable to portal systems because of portal systems' particularities shown above.This paper proposes an improved access control model for portal systems:P-RBAC.The model is based on RBAC by extending it both on concepts and on behaviors.The static and dynamic models of P-RBAC are described,and then a detailed discussion of the rules and policies on both models is given.The application of P-RBAC in real environment proves that it can be a possible and efficient solution for the access control in portal systems.
出处 《计算机工程与应用》 CSCD 北大核心 2007年第12期119-123,共5页 Computer Engineering and Applications
基金 国家自然科学基金(the National Natural Science Foundation of China under Grant No.60573126) 国家重点基础研究发展规划(973)(the National Grand Fundamental Research 973 Program of China under Grant No.2002CB312005)。
关键词 门户 RBAC 访问控制 P-RBAC portal RBAC access control P-RBAC
  • 相关文献

参考文献10

  • 1Wege C.Portal server technology[J].IEEE Internet Computing,2002,6:73-77.
  • 2JSR168:Portlet Specification,Java Community Process[EB/OL].[2003].http://www.jcp.org/en/jsr/detail?id=168.
  • 3WSRP.OASIS Web Services for Remote Portlets TC[EB/OL].[2003].OASIS Open.http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=wsrp.
  • 4Sandhu R,Coyne E,Feinstein H,et al.Role-based access control model[J].IEEE Computer,1996,29(2):38-47.
  • 5Park J,Sandhu R,Ahn G.Role-based access control on the Web[J].ACM Transactions on Information and System Security,2001,4(1):37-71.
  • 6Al-Kahtani M,Sandhu R.A model for attribute-based user-role assignment[C]//Proceedings of the 18th Annual Computer Security Applications Conference,Las Vegas NV,December 2002.IEEE,2002:353-362.
  • 7BEA Systems,Inc.WebLogic Administration Portal Tutorial[EB/OL].[2005].http://e-docs.bea.com/wlp/docs81/zip/ beawlp81 docs-pdf.zip.
  • 8Buehler D,Hurek T.IBM WebSphere Portal V5.1 Security Overview[EB/OL].[2005].IBM Corp.http://www.ibm.com/ developerworks/websphere/library /techarticles/0511_buehler/051 1_buehler.html?S_TACT=105 AGX52&S_CMP=cn-a-wes.
  • 9中科院软件所.网驰平台门户中间件(OncePortal)[EB/OL].http://www.once.com.cn/.
  • 10Nyanchama M,Osborn S L.The role graph model and conflict of interest[J].ACM Transactions on Information and System Security,1999,2(1):3-33.

共引文献1

同被引文献12

引证文献3

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部