首页 | 官方网站   微博 | 高级检索  
     

基于RBAC改进模型的角色权限及层次关系分析
引用本文:吕宜洪,宋瀚涛,龚元明.基于RBAC改进模型的角色权限及层次关系分析[J].北京理工大学学报,2002,22(5):611-614.
作者姓名:吕宜洪  宋瀚涛  龚元明
作者单位:北京理工大学,计算机科学与工程系,北京,100081
基金项目:北京市质量技术监督局信息化建设项目;;
摘    要:针对著名的RBAC96模型的不足之处,结合私有权限、部门权限和权限属性变化等问题,对角色权限及角色层次关系进行了分析,提出了一个改进的角色层次化关系模型.该模型引入特征权限等概念,通过定义一般继承、私有化继承、公有化继承和无特征继承等新的角色继承方式建立角色层次化关系模型.新模型比RBAC96模型更加简化和易于理解,且具有更强的可伸缩性,特别适合于在复杂的角色层次关系中应用,例如网络操作系统、大型数据库、分布式应用等.

关 键 词:基于角色的访问控制  访问控制  权限继承  角色层次关系
文章编号:1001-0645(2002)05-0611-04
收稿时间:2001/11/19 0:00:00
修稿时间:2001年11月19日

An Analysis About Role Permission and Role Hierarchy Based on an Improved Role Based Access Control Model
LV Yi-hong,SONG Han-tao and GONG Yuan-ming.An Analysis About Role Permission and Role Hierarchy Based on an Improved Role Based Access Control Model[J].Journal of Beijing Institute of Technology(Natural Science Edition),2002,22(5):611-614.
Authors:LV Yi-hong  SONG Han-tao and GONG Yuan-ming
Affiliation:Dept. of Computer Science and Engineering, Beijing Institute of Technology, Beijing100081, China;Dept. of Computer Science and Engineering, Beijing Institute of Technology, Beijing100081, China;Dept. of Computer Science and Engineering, Beijing Institute of Technology, Beijing100081, China
Abstract:Combined with the issues of private permissions, department permissions and changes of permission types, subjects of role permissions and role hierarchies are analyzed in more depth and an improved role hierarchy model for role based access control (RBAC) is introduced against the imperfections of the famous RBAC96 model. Some new concepts such as special permissions are presented in the model. Concepts like normal inheritance, privatizing inheritance, publicizing inheritance and special-without inheritance are defined, thus a new role hierarchy model is formulated. It is simpler and more comprehensible to describe the same role relationships in the improved model when compared with RBAC96. It is more flexible, and more suitable to be used in large-scale role hierarchies such as operating systems, DBMS, distributed applications, etc.
Keywords:RBAC  access control  permission inheritance  role hierarchy
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《北京理工大学学报》浏览原始摘要信息
点击此处可从《北京理工大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号