首页> 外文会议>International Conference on Information Security >Uni-ARBAC: A Unified Administrative Model for Role-Based Access Control
【24h】

Uni-ARBAC: A Unified Administrative Model for Role-Based Access Control

机译:Uni-ARBAC:基于角色的访问控制的统一管理模型

获取原文

摘要

Many of the advantages of Role Based Access Control (RBAC) accrue from the flexibility of its administrative models. Over the past two decades, several administrative models have been proposed to manage user-role, permission-role and in some cases role-role relations. These models are based on different administrative principles and bring inherent advantages and disadvantages. In this paper, we present a unified model, named Uni-ARBAC, for administering user-role and permission-role relations by combining many of the administrative principles and novel concepts from prior models. For example, instead of administering individual permissions Uni-ARBAC combines permissions into tasks which are assigned to roles as a unit. Slightly differently, users are assigned to user-pools from where individual users are assigned to roles. The central concept of Uni-ARBAC is to integrate user-role and task-role administration into a more manageable unit called an Administrative Unit (AU). AUs partition roles, tasks and user-pools and they are organized in a rooted tree hierarchy. Administrative users are assigned to AUs with possibility of restricting their authority to user-role assignment or task-role assignment. While most existing models assume existence of administrative roles for managing regular roles, we present an approach for engineering AUs based on structured partitioning of roles and tasks.
机译:基于角色的访问控制(RBAC)的许多优点来自其管理模型的灵活性。在过去的二十年中,已经提出了几种管理模型来管理用户角色,权限角色以及某些情况下的角色角色关系。这些模型基于不同的管理原则,并带来固有的优缺点。在本文中,我们提出了一个统一的模型Uni-ARBAC,该模型通过结合先前模型中的许多管理原则和新颖概念来管理用户角色和权限角色关系。例如,Uni-ARBAC而不是管理单个权限,而是将权限合并到分配给角色为一个单元的任务中。稍有不同,将用户分配给用户池,从那里将各个用户分配给角色。 Uni-ARBAC的中心概念是将用户角色和任务角色管理集成到一个更易于管理的单元中,称为管理单元(AU)。 AU划分角色,任务和用户池,它们以根目录树层次结构组织。将管理用户分配给AU,并可能将其权限限制为用户角色分配或任务角色分配。虽然大多数现有模型都假定存在管理常规角色的管理角色,但我们提出了一种基于角色和任务的结构化分区来设计AU的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号