期刊文献+

一种新颖的面向方面的Web应用访问控制方法 被引量:2

Novel aspect-oriented Web application access control method
下载PDF
导出
摘要 基于角色的访问控制是一种传统的软件安全技术;支持Web应用开发的框架技术层出不穷,如struts和spring框架基于MVC设计模式对Web应用进行了有效地解耦合。在这些框架技术下,如何充分使用这些框架带来的优势,实现一种配置灵活、扩展性强、易于维护的访问控制机制成为一个新的挑战。结合AOP、反射、上下文传播、XML技术给出了一种新颖的访问控制实现方法,这种方法能够同基于MVC设计模式的框架有机地结合起来,不仅使访问控制代码集中管理,而且在实现访问控制的同时,保持了原有Web应用的松耦合结构。 Role-based access control is a traditional software security technology;Web application framework technology comes out continually,such as struts and spring,they decouple Web application by MVC design pattern.It is a challenge to make full use of these frameworks,and implement a flexibly configured,scalable and maintainable access control mechanism.We present a novel access control method based on AOP,reflection,context propagation,XML technology.The method can work with MVC framework seamlessly.It not only makes the access control code be centrally controlled,but also keep Web application loose coupled at the same time.
出处 《计算机工程与应用》 CSCD 北大核心 2007年第36期110-113,共4页 Computer Engineering and Applications
基金 国家自然科学基金(the National Natural Science Foundation of China under Grant No.90104020) 国家高技术发展计划(863)(the NationalHigh- Tech Research and Development Plan of China under Grant No.2001AA113020) 国家重点基础研究发展规划(973)(the NationalGrand Fundamental Research 973 Program of China under Grant No.G1999032703)
关键词 访问控制 WEB应用 AOP 上下文传递 access control Web application AOP context propagating
  • 相关文献

参考文献5

二级参考文献14

  • 1谢新泉,石锐,刘智.基于UML的管理信息系统中用户权限管理的设计和实现[J].计算机工程与应用,2004,40(17):187-189. 被引量:6
  • 2Ferraiolo D F,Barkley J F,Kuhn D R.A Role Based Access Control Model and Reference Implementation within a Corporate Intranet[J].ACM Transactions on information Systems Security,1999,2 (1):34-64.
  • 3STAIRRM REYNOLDSGW 张靖.信息系统原理[M].北京:机械工业出版社,2000..
  • 4Philippe Li-Thaio-Te,Jessie B Kennedy,John Owens.Assessing Inheritance for the Multiple Descendant Redefinition Problem in OO Systems[C].In:Object-Oriented Information Systems 4th International Conference OOIS'97,1997.
  • 5Buschmann Frank et al.Pattern-Oriented Software Architecture[M]. John Wiley & Sons Ltd, 1996.
  • 6Kiczales G et al.Aspect-Oriented Progrmming[C].In:Proceedings of the European Conference on Object-Oriented Progrmming,1997.
  • 7J Viega,JT Bloch,P Chandri.Applying Aspect-Oriented Programming to Security[J].Cutter IT Journal,14(2).
  • 8.[EB/OL].http://www.comp.lancs.ac.uk/computing/aop/.,.
  • 9.[EB/OL].http://aosd.net/technology/research.php.,.
  • 10David F.Ferraiolo,Ravi S.Sandhu,Serban Gavrila.,et al.Proposed NIST standard for role-base access control[J].ACM Transactions on Information and Systems Security,2001,(3):224-274.

共引文献9

同被引文献6

引证文献2

二级引证文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部