【24h】

Capability-Based Delegation Model in RBAC

机译:基于能力的授权模式在RBAC中

获取原文

摘要

For flexible and dynamic resource management in environments where users collaborate to fulfill their common tasks, various attempts at modeling delegation of authority have been proposed using the role-based access control (RBAC) model. However, to achieve a higher level of collaboration in large-scale networked systems, it is worthwhile supporting cross-domain delegation with low administration cost. For that purpose, we propose a capability-role-based access control (CRBAC) model, by integrating a capability-based access control mechanism into the RBAC96 model. Central to this scheme is the mapping of capabilities to permissions as well as to roles in each domain, thereby realizing the delegation of permissions and roles by capability transfer. By taking this approach of capability-based access control, our model has the advantages of flexibility and reduced administration costs. We also demonstrate the effectiveness of our model by using examples of various types of delegation in clinical information systems.
机译:对于用户在用户协作以满足其共同任务的环境中,已经使用基于角色的访问控制(RBAC)模型提出了各种尝试委托权限的各种尝试。然而,为了在大规模联网系统中实现更高水平的合作,值得支持低管理成本的跨领域代表团。为此目的,我们通过将基于能力的访问控制机制集成到RBAC96模型中,提出了一种基于能力的访问控制(CRBAC)模型。该方案的核心是对权限的功能以及在每个域中的角色映射,从而通过能力传输来实现权限和角色的委派。通过采用基于能力的访问控制方法,我们的模型具有灵活性和减少的管理成本。我们还通过在临床信息系统中使用各种类型的委派的示例来证明我们的模型的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号