【24h】

An Extended Permission-Based Delegation Authorization Model

机译:基于扩展权限的委托授权模型

获取原文

摘要

The characteristics of delegation are analyzed and defined in this paper, including time, totality, level, multi-delegation, agreement and revocation. Based on RBAC, an extended role and permission-based delegation model is redefined by separating delegate roles from original roles. Security administrators (SAs) and ordinary users have different functions and duties in the authorization and delegation. SAs only participate in the original authorization work, but ordinary users can engage in role assignment more actively. They can reassign permissions to roles. As a result the extended role and permission-based delegation model hold more flexibility in the complex application environment. The temporal constraints of delegation also imply the complexity of delegation revocation.
机译:本文分析和定义了委派的特征,包括时间,总数,级别,多重授权,协议和撤销。基于RBAC,通过将委托人角色与原始角色分开来重新定义扩展角色和基于权限的委托模型。安全管理员(SA)和普通用户在授权和委派中具有不同的功能和职责。 SA仅参与原始授权工作,但普通用户可以更积极地参与角色分配。他们可以将权限重新分配给角色。结果,扩展角色和基于权限的委托模型在复杂的应用程序环境中拥有更大的灵活性。委派的时间限制也暗示了委派撤销的复杂性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号