摘要
W eb环境下的企业信息系统容易受到来自企业内外的安全威胁,需要一种灵活高效的访问控制来保护企业的资源。在给出RBAC基本概念和XACML策略机制的基础上,提出了基于XACML和RBAC的访问控制模型。
Enterprise Information System based on Web technology is easy to be threatened from interior or exterior, It's necessary to develop an effective and flexible access control mechanism to protect enterprise's assets. After introducing basic concept of RBAC and XACML,this paper proposes access control system based on XACML and RBAC.
出处
《计算机应用与软件》
CSCD
北大核心
2006年第8期65-67,共3页
Computer Applications and Software