多政策的两层协同应用存取控制模型
Multilevel Multi-policy Access Control Model for Collaborative Application
-
摘要: 总结了国内外存取控制研究,分析了目前基于角色的存取控制应用于协同系统时存在的一些问题.针对这些问题,给出了一个用于协同应用系统的存取控制框架.该框架包括两个子部件:基本模型和角色模型.基本模型规定了操作权限之间的依赖关系以及如何进行操作权限比较,并将权限与对具体对象的操作相关联,使得该模型较为直观.此外只要系统中Broker的实现支持,该模型能够实现任意粒度级的存取控制.角色模型对RBAC96的角色概念重新给予了定义,将角色的允许集划分为三部分:公共权限、私有权限和保护权限.角色允许集的划分使用户可以更加灵活地定义角色,方便地控制角色的私有信息不被其他角色所访问,有效地减少了辅助角色的定义.Abstract: An access control paradigm composed of basic model and role model is proposed for collaborative applications.Basic model specifies the relationship among privileges and the way of ranking privileges.It relates privilege with operationson the objectsso the model appears more straight forward. Moreoverif Brokers’implementation permitsthe model can support any grained access control.Role model re-defines the role concept of RBAC96divides the permissions of role into public permissions protect permissions and private permissions.It allows user to define roles more flexiblyprevents private permissions of roles from being inherited and reduces the definition of ancillary roles.
下载: