摘要
针对嵌入式Web系统自身的安全,结合嵌入式Web系统的特点,在对基于角色的访问控制模型研究的基础上对其进行简化修改,去掉角色继承的复杂模式,在此基础上提出了适用于嵌入式Web系统的"用户-角色-权限集(业务-页面-操作)"访问控制设计方案。并利用CGI技术实现了特定的嵌入式Web应用系统的访问控制功能,限制了合法用户对嵌入式Web系统资源的访问,防止了非法用户的侵入或因合法用户的不慎操作而造成的破坏。对实现的Web应用系统进行了测试,测试结果表明该模型具有良好的功能。
For the security of embedded Web system itself,combined with the characteristics of embedded Web system and based on the research on the model,it simplifies RBAC model to remove the role of complex patterns of inheritance and gives the embedded Web solution for access control system that is "user-role-privilege set(business-page-operation)"model.The embedded Web access control system is achieved through CGI technology,limiting user access to embedded Web systems resources,and preventing the intrusion of unauthorized users or the damage caused by careless operation of legitimate users.The Web application system was tested,and the test results show that the model has good functions.
出处
《计算机技术与发展》
2011年第8期228-232,共5页
Computer Technology and Development
基金
国家高技术(863)计划项目(2006AA01Z208)
江苏省科技支撑计划项目(BE2009157)
南邮青蓝计划项目(NY208023)