摘要
针对现有用户-用户的层次化角色授权模型存在授权冲突问题,基于授权的时限和约束限制规则,对层次化角色的授权组件、相关性质以及互斥角色的约束限制规则进行了描述。提出了一种层次化角色的受限授权模型,该模型满足最小特权和职责分离两安全原则。给出了角色授权的生成和撤销算法,并对该模型的正确性和完整性进行了讨论。最后给出了实现该模型的体系架构,并通过应用实例验证了模型的有效性和实用性,较好地解决了角色层次上的授权冲突问题。
Existing user-user hierarchical role-based delegation models do not solve the problem of delegating conflicts. Role-based delegation module of RBAC with its properties and constraint rules are described and a hierarchical role-based constrained delegation model (HRCDM) is presented, which satisfies least privilege and separation of duty principles. A delegation algorithm and a revocation algorithm are given, and then the soundness and completeness of HRCDM is discussed. Finally, HRCDM is achieved in a system structure, and is proved available and useful by a delegation application example. The problem of delegating conflicts is solven efficiently.
出处
《计算机工程与设计》
CSCD
北大核心
2008年第15期3843-3845,3855,共4页
Computer Engineering and Design