支持授权的基于角色的访问控制模型及实现
Authorization Supported Role-Based Access Control Model and Its Implementation
-
摘要: 现有的基于角色的访问控制模型多采用集中授权管理方式,不能满足大型复杂协作系统的需求.文中对RBAC96模型进行扩展,形成了支持授权的基于角色的访问控制模型.该模型引入角色语境作为自主授权活动的依据,通过语境部件授权极限值、授权域、授权类型以及撤销类型的定义,以支持灵活的自主授权活动,并支持多步授权,允许安全管理员对系统进行宏观安全控制.对该模型的基本部件和规范进行了描述,并且给出授权活动的实现算法和应用实例.Abstract: Role-based access control models introduced in literature cannot satisfy the requirements of complex system because of using central administration.A new model is introduced through extending RBAC96.This model develops ROLECONTEXT as the criterion of auto-authorization activity.Four ROLECONTEXT componentsnamely authorization maximumauthorization regionauthorization type and revocation type are defined to support flexible and mult-i step authorization.This makes the model permit security manager to control the system at a higher level.Core component and specifications of the new model are given.Moreoveralgorithm for authorization and examples are illustrated.
下载: