摘要
近年来RBAC(Role-B ased Access Contro1)及TBAC(Task-B ased Access Contro1)模型得到广泛的研究。在比较了一些现有访问控制模型的各自特点和适用范围,针对现有模型的不足,为了提高信息系统的安全性、通用型和实用性,通过结合RBAC及TBAC模型各自的优点,提出了一个新型的访问控制模型TRBAC(Task-Role B ased Access Contro1),描述了TRBAC模型结构和特点,阐述了模型对最小权限原则、职权分离原则、数据抽象原则及角色层次关系的支持,并指出将来工作的主要目标。
The research work of RBAC(role-based access Control)and TBAC(task,based access control )is greatly emphasized in recent years. This paper compares the characteristics and applicability spectrum of some recent models. To the deficiency of the existing model,in order to improve the security, compatibility and practicability of application systems,through combining the advantages of RBAC and TBAC model,a new-type model,T-RBAC( task-role based access control ), is discussed. The configuration and characteristics of the model is described. The support of least privilege,separation of duties ,data abstraction and roles hierarchies in the model is explained.The main goal of future research is presented.
出处
《东北电力大学学报》
2006年第4期36-40,共5页
Journal of Northeast Electric Power University
基金
东北电力大学博士科研启动基金
国家自然科学基金(60503016)
国家自然科学基金重大项目(60496321)