摘要
为适应多域多应用环境下的安全互操作的需求,本文通过扩展 RBAC96模型有关概念,增加其对多域环境下多应用的刻画,通过引入全局角色、域角色和关联角色概念,提出了一种多域多应用访问控制模型 DPM。通过对PMI 授权管理构架进行扩展,实现了 DPM 模型,为多域多应用环境下的安全互联提出了一个实际的解决方案。
According to the security requirements in multi domain & multi application environment, an access control model called DPM (Distributed Privilege Model)is presented by adding application aspect into RBAC96 model and introducing global role, domain role and correlation role concept. Through extending PMI(Privilege Management Infrastructure), DPM model is realized. In conclusion, it proposes a practical scheme for the authorization and privilege management in multi-application and multi-domain context.
出处
《计算机科学》
CSCD
北大核心
2006年第4期281-283,共3页
Computer Science
关键词
PMI
访问控制
授权模型
Privilege management infrastructure, Access control, Authorization model