摘要
角色委托是RBAC模型需要支持的一种重要安全策略。其主要思想是系统中的主动实体将角色委托给其他主动实体,以便以前者名义执行特定的工作。提出一个基本的角色委托模型,在该模型的基础上,从应用出发,分别在时间约束、部分委托约束、角色依赖约束、层次角色模型的委托限制方面进行了扩展,给出了委托权限的回收方法,为模型在实际环境中的应用奠定了基础。
Role delegation is an important security policy that should be supported for RBAC model.The basic idea of delegation is that some active entities in a system delegate their roles to other active entities to carry out some specific functions on behalf of the former.This paper presents a basic role-based delegation model.Based on it and proceeding from the application,some extensions to this model are explored,including time constraint,partial delegation constraint,role dependency constraint,and delegation restriction of hierachical role model.It provides the means of revocation of delegation permission,and lays the foundation for the application of the model in practical conditions.
出处
《计算机应用与软件》
CSCD
2010年第1期210-212,230,共4页
Computer Applications and Software
关键词
RBAC
委托
约束
RBAC Delegation Constraint