摘要
文章提出了一种新的基于RBAC的角色层次控制与用户业务限制混合权限管理模型(N-RBAC),定义了角色的共有权限、基于层次控制的角色影子权限以及用户的私有业务约束;该模型比传统的RBAC或其修正模型具有更高的灵活性和更广的适用性,解决了角色与用户之间共性与个性的矛盾,既简化了信息系统中对用户授权管理,又使相同角色的用户对相同的功能模块可以有不同的操作限制;详细讨论了N-RBAC的设计原理与实现方法;应用实践表明该模型使用方便,设置灵活,能有效满足各类信息系统权限管理的需要。
A new authoritative management model, N-RBAC, which is based on the combination of role hierarchy control with the user transaction limit is presented. The public authority of the role, the shadow authority based on the role hierarchy control, and the user's private transaction restraint are defined. Compared with the traditional RBAC or its revised model, the N-RBAC is more flexible and efficient, the contradiction of generality and individuality between the role and the user is resolved. It not noly simplifies the user authorization management in the information system, but it also enables those users with the same role to have the different operating limitation to the same function module. The detailed discussions are given about the principle of design and the implementation method of the N-RBAC. It is proved in application practice that the proposed model is easy in operation and flexible in establishment.
出处
《合肥工业大学学报(自然科学版)》
CAS
CSCD
北大核心
2008年第11期1782-1785,1804,共5页
Journal of Hefei University of Technology:Natural Science
基金
国家科技创新基金资助项目(05C26222120349)
安徽省教育厅自然科学基金资助项目(kj2007a124zc)
关键词
信息系统
权限管理
角色
基于角色的访问控制
层次控制
information system
authority management
role
role-based access control(RBAC)
hierarchy control