上海大学学报(自然科学版)

• 计算机工程与科学 • 上一篇    下一篇

增强约束的角色访问控制模型

周明,曾俊冬,蔡玉华   

  1. 上海大学 计算机工程与科学学院,上海 200072
  • 收稿日期:2006-12-13 修回日期:1900-01-01 出版日期:2007-10-20 发布日期:2007-10-20
  • 通讯作者: 周明

Role-Based Access Control Model with Enhanced Constraints

ZHOU Ming,ZENG Jun-dong,CAI YU-hua   

  1. School of Computer Engineering and Science, Shanghai University, Shanghai 200072, China
  • Received:2006-12-13 Revised:1900-01-01 Online:2007-10-20 Published:2007-10-20
  • Contact: ZHOU Ming

摘要: 分析NIST标准RBAC模型的约束机制,针对授权过程和对客体访问过程约束能力不足,通过对约束的扩展和将具有约束能力的业务逻辑映射至模型约束中,形成一种增强约束的基于角色的访问控制模型.给出了该模型的形式化定义,并对其安全性作了简要分析.

关键词: 基于角色的访问控制, 权限, 约束

Abstract: The mechanism of constraint in NIST standard of role-based access control (RBAC) is analyzed. To resolve the problem of shortages of constraints in the authorization process and accessing objects process, a novel RBAC model with enhanced constraints is proposed by extending the constraints and mapping true-life operation that has constrainted capability into RBAC model. The formalization definitions of the new model are presented and its security analyzed.

Key words: constraint, permission , rose-base access control (RBAC)