期刊文献+

Web应用中的访问控制系统设计 被引量:1

Design of Access Control System for Web Application
下载PDF
导出
摘要 传统的访问控制技术DAC,MAC不适于Web环境,RBAC/Web的响应效率较低.在分析了RBAC模型以及RBAC/Web参考实现的基础上,提出了结合RBAC思想与页面组件技术实现高效Web访问控制的思路,描述了RBAC数据库设计、身份验证与ARS激活、权限验证组件设计的方法.工程实践表明,该方案解决了RBAC/Web的效率问题,能够满足中、小型Web应用项目对访问控制系统的要求. The traditional access control technics as DAC and MAC are not suitable for web environment,because RBAC/Web model has low efficiency. The author analyzed the RBAC model and the reference implementation of RBAC/Web, put forward an idea of achieving high-performance of access control for web application by the combination of RBAC and component technology. The methods of RBAC database design, validation and ARS activation, page component design are described. It's proved by project that the means described in this paper solved the inefficient problem of RBAC/Web, and met the demands of access control for middle scale and small scale web applications.
出处 《西安工业大学学报》 CAS 2008年第2期163-167,共5页 Journal of Xi’an Technological University
关键词 WEB应用 授权证 访问控制 RBAC Web application authentication access control RBAC
  • 相关文献

参考文献5

  • 1[2]Ferraiolo D,Kuhn D R.Role-Based Access Controls[C]//15th National Computer Security Conference,Baltimore:NIST,1992:554.
  • 2[3]Sandhu R,Coyne E J,Feinstein H L.Role-based Access Control Models[J].IEEE Computer,1996,29 (2):38.
  • 3[4]Ferraiolo D,Sandhu R,Gavrila S.Proposed NIST Standard For Role-Based Access Control[J].ACM Transactions on Information and System Security,2001,4(3):224.
  • 4[5]Ferraiolo D,Barkley J F.Specifying and Managing Role-based Access Control within A Corporate Intranet[C]//ACM Workshop on Role-Based Access Control,New York:ACM,1997:77.
  • 5[6]Ferraiolo D,Barkley J F,Kuhn D R.A Role Based Access Control Model and Reference Implementation within a Corporate Intranet[J].ACM Transactions on Information Systems Security,1999,2(1):34.

同被引文献15

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部