摘要
本文为 RBAC模型提出了一个基于着色 Petri网的策略规格说明和分析的架构 .Petri网能够捕获基数、责任分离等约束 ,而且能对优先和依赖约束进行说明 .使用 Petri网的可达到性分析技术对 RBAC策略进行正确性验证 .
The crucial issue of verification of role based access control policies has not been adequately investigated. In this paper, we develop a colored Petri net based policy specification and analysis framework for an RBAC model. The Petri net model can capture all the cardinality and separation of duty constraints. Moreover, the model also allows specification of the precedence and dependency constraints. We use the Petri net reachability analysis technique for verifying correctness of RBAC policies.
出处
《小型微型计算机系统》
CSCD
北大核心
2004年第5期827-832,共6页
Journal of Chinese Computer Systems