摘要
针对经典RBAC(Role Based Access Control)模型在复杂应用系统中操作繁琐以及难以映射组织结构等不足之处,提出了一种支持角色双向继承的约束RBAC模型BI-RBAC。该模型对经典的RBAC模型进行扩展,增加虚拟角色及其层次结构以支持角色的双向继承,并定义资源操作的概念。给出模型的形式化定义的同时,设计了访问控制算法。模型在自主开发的大型平台软件钱塘中间件平台软件中得到了应用,可较好地支撑恒生证券交易系统等大型软件系统。
For the inadequacies of classic RBAC model such as the cumbersome operation in complex application systems and the difficulty to map organisation structures,we propose a constrained RBAC model supporting role bidirectional inheritance,BI-RBAC.The model extends the classic RBAC model,adds virtual role and its hierarchy to support the role bidirectional inheritance,and define the concept of resource operation.While giving the formal definition of the model,the access control algorithm is designed as well.The model has been applied to the self-developed large-scale Jtang Middleware platform,and can well support the Hundsun stock exchange system and other large application systems.
出处
《计算机应用与软件》
CSCD
2011年第6期121-124,共4页
Computer Applications and Software
基金
国家发展和改革委员会信息安全专项产品产业化专项(20062981)
关键词
访问控制
虚拟角色
虚拟角色层次结构
双向继承
Access control Virtual role Virtual role hierarchy Bidirectional inheritance