摘要
针对分布式协作环境中的授权问题,基于委托模型和RBAC模型,提出一种基于委托的分布式动态授权策略。通过扩展RBAC模型的元素集和静态授权操作,并由委托者动态创建临时委托角色和委托授权,支持"部分角色转授权"。系统授权采用三级层次结构实现,并给出了动态委托授权过程。系统实现及应用表明了其能够适应分布协作环境下的分布动态授权需求,遵循"最小特权"原则。
Concerning the authority in distributed environment for collaboration, a dynamic authorization scheme was presented based on delegation and RBAC model. The scheme supports partial role delegation, by expanding element sets of RBAC model, enlarging static authorization operations, and allowing the delegator to create temporary delegation roles and assign others (the delegatee) to the particular roles. The scheme was implemented by three-level frameworks, and the operating process about how to authorize dynamically in delegation model was described. The application shows that the scheme can adapt to distributed and dynamic environment, and follow the least privilege principle.
出处
《计算机应用》
CSCD
北大核心
2008年第6期1365-1368,共4页
journal of Computer Applications
基金
国家自然科学基金资助项目(60773118)
国家863计划项目(2006AA01A109)
现代通信国家重点实验室基金资助项目(9140C1101050706)
关键词
访问控制
委托授权
角色访问控制
公钥基础设施
特权管理基础设施
access control
delegation
Role-Based Access Control (RBAC)
Public Key Infrastructure (PKI)
Privilege Management Infrastructure (PMI)