摘要
基于矩阵型组织方式下的系统产生了很多新的安全访问控制方面的问题,RBAC虽然是很好的选择,但传统的RBAC96模型在组织结构管理和客体的交叉访问方面存在着一定的局限性。针对这两方面问题,对RBAC96模型进行了扩展和改进,提出了一种基于矩阵型组织机构和角色访问控制模型——MO-RBAC。该模型着重于组织结构的管理和客体的协同访问控制,使得模型一方面具有了很好的灵活性和易用性,另一方面,提高了系统的安全,防止了相关角色对客体的非法访问。
Systems based on matrix organization brought about many new issues about access control. Although role based access control is a perfect choice, there are some limitations in the traditional RBAC96 model about organization management and objects crossed accessing. Aim at these problems,puts forward a new improved access control model, the matrix organization and role based access control (MO - RBAC), whieh is based on the RBAC96 model. This model attaches importance on organization structure management and cooperative accessing control of objects, which on the one hand has very good flexibility and convenience, on the other hand, can avoid related roles' illegal access and unauthorized operation.
出处
《计算机技术与发展》
2009年第4期180-183,共4页
Computer Technology and Development
基金
国家863子课题(2002AA142110)
关键词
矩阵型组织
RBAC
访问控制
客体
matrix organization
role based access control
access control
object