【24h】

RBAC-Based Access Control for SaaS Systems

机译:SaaS系统基于RBAC的访问控制

获取原文

摘要

SaaS (Software as a Service) deliver software as a service over the Internet, eliminating the need to install and run the application on the customers' own computers and simplifying maintenance and support. Access control is an important information security mechanism, according to user identity and the attribution of a predefined group of users to restrict access to certain information items, and limit the use of certain functions. In view of the features of multi-tenant, if we apply existing access control methods to SaaS systems directly, the following problems will appear: (1) role name conflicts (2) cross-level management (3) the isomerism of tenants' access control. This paper propose the S-RBAC model which can be applied to SaaS systems, this model extends from the RBAC model and ARBAC97 model, it uses layered structures to achieve system-level and tenant-level access control, solves the SaaS system access control problems. And we put forward a way to implement the access control module for SaaS systems based on S-RBAC model.
机译:SaaS(软件即服务)通过Internet交付软件即服务,从而无需在客户自己的计算机上安装和运行应用程序,并简化了维护和支持。访问控制是一种重要的信息安全机制,它根据用户身份和一组预定义的用户属性来限制对某些信息项的访问,并限制对某些功能的使用。鉴于多租户的特性,如果我们将现有的访问控制方法直接应用于SaaS系统,则会出现以下问题:(1)角色名称冲突(2)跨级别管理(3)租户访问的异构性控制。本文提出了一种可以应用于SaaS系统的S-RBAC模型,该模型是从RBAC模型和ARBAC97模型扩展而来,它采用分层结构来实现系统级和租户级的访问控制,解决了SaaS系统的访问控制问题。 。并提出了一种基于S-RBAC模型的SaaS系统访问控制模块的实现方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号