基于能力-角色访问控制模型
apability-Role Base Access Control Model
基于角色访问控制模型已经成为解决安全管理问题的最广泛的、最有效的访问控制模型之一。但在一个基于角色的访问控制模型管理下的交互系统中,依然存在管理员可在其权限内不受约束的向任意用户进行非冲突角色授权的风险。为解决这一问题,在本文中我们提出了基于能力-角色访问控制模型。该模型继承了基于角色的访问控制模型的灵活性,并通过对预定义被授权者的能力范围,来达到对用户授权操作的限制。文章最后,通过案例对于模型的适用性进行了讨论。
Role-based access control model has become one of the most powerful and generalized access control model for handling security management problems. However, in a collaboration system under RBAC controlling, there is still a risk that there is no rules to restrict administrators to assign the disconflict roles to any user within their competence. To cope with this risk, in this paper we propose a Capability-Role based Access Control model. The CRBAC model inherits the RBAC model of flexibility, and predefines the scope of authorized persons' capacity to the restrictions on the authorized operations. Applicability of the CRBAC model has been evaluated through some case studies at the end of this paper.
栗静文
计算技术、计算机技术
访问控制RBACRBAC
ccess ControlRBACRBAC
栗静文.基于能力-角色访问控制模型[EB/OL].(2010-12-07)[2025-08-23].http://www.paper.edu.cn/releasepaper/content/201012-180.点此复制
评论