摘要
针对企业级信息系统用户、角色多,权限关系和客体资源复杂等特点,在分析了多种访问控制技术的基础上,提出了一种新的基于角色的访问控制模型及其安全策略。此模型对传统的RBAC模型进行了优化处理,将分级授权、最小化授权、角色授权继承等策略相结合,以支持多种细粒度的访问控制。实验证明,能提高企业级信息系统的安全性和运行效率。
For many users and roles of enterprise information system, permissions and complex object resources, based on the analysis of a variety of access control technologies, a new role-based access control model and its security policy are come UP. The traditional RBAC model is optimized by this model, and rating authorization, minimize authorization and role authorization inheritance are combined to support a variety of fine-grained access control. Experiments proved that it can improve the safety and operating efficiency of the enterprise information systems.
出处
《价值工程》
2012年第5期149-150,共2页
Value Engineering
基金
2010年江苏省高等学校大学生实践创新训练计划基金支持项目
关键词
企业级信息系统
访问控制模型
角色
安全策略
enterprise information system
access control model
role
security policy