摘要
传统访问控制实现机制在大规模信息系统的权限管理上具有较大的复杂度.本文研究在授权关系表的基础上对访问控制信息的聚合处理以实现授权管理.在用户端、权限端的访问控制聚合分别形成基于角色、基于分组的方法,通过对上述两种方法的对比,分析了访问控制聚合的有效性,并通过实际系统验证了上述结论.研究结果表明,访问控制聚合是解决大型信息系统访问控制的有效方法,基于角色的方法通常能更易于满足系统的安全要求.
Implementation mechanism of traditional access control is much more complex in large-scale information system. Aggregations of access control based on authorization relations are researched in this paper to implement management of authorization. Aggregations of access control in user side and permission side form role-base and group-based method, respectively. Compared with each of the two methods, validity of aggregation of access control is analyzed, and the conclusion is verified in real application. Research result indicates that aggregation of access control is effective method to solve large information system, and role-based method is usually easy to meet the security requirements.
出处
《小型微型计算机系统》
CSCD
北大核心
2008年第11期2167-2170,共4页
Journal of Chinese Computer Systems
基金
国家"八六三"计划基金项目"科学数据网格"(2004AA104240)资助
中国科学院信息化建设重大项目科学数据库(INF105-SDB)资助