摘要
文章介绍了基于角色的安全访问控制基本模型 ,并根据企业结构多层次性的特点 ,对模型提出改进意见 ,即在建立会话管理时 ,对角色加以动态限制 ,规定用户访问范围。根据改进模型设计实现方案。该方案具有较大的灵活性 ,使系统的安全性得到提高 ,简化了授权管理 。
This article introduces the Role-Based Access Control model (RBAC) and proposes an improved model according to the characters of enterprise. Dynamic constraints on role are added when we establish the session, which can control the users' date access range. As a result of improved model, a role-based security scheme is designed. It strengthens the security of the system and simplifies the management of authority and matches the security requirements of enterprise.
出处
《南华大学学报(社会科学版)》
2003年第2期49-51,71,共4页
Journal of University of South China(Social Science Edition)