摘要
从主体和客体两方面探讨了访问控制问题,提出了一种基于角色和任务的访问控制模型。该模型不但考虑了访问控制的主体(用户/角色),以及访问控制所处的环境(静态/动态),而且引入受控对象层次和操作类型层次概念,并定义相应的处理规则进行权限定义,使权限定义变得更加简单明了。
An improved task-role access control model was presented. Subject(user/role) and condition( dynamic/ static) were caculated in this model. Two concepts were introduced :object hierarchy and operation hierarchy. On the basis of two concepts , the rules for defining permissions was proposed. The experiments showed that the method could simplify the definition of permissions.
出处
《贵州科学》
2009年第3期51-53,共3页
Guizhou Science
基金
贵州省科学技术基金(20082045)
贵州省国际科技合作重点项目计划(编号:黔科合外G字(2007)400112号)
贵州大学研究生创新基金(2007007)资助课题
关键词
安全约束
RTBAC
权限管理
security constraints, RTBAC, authorization management