首页> 外文会议>ACM symposium on access control models and technologies >The Role Control Center: Features and Case Studies
【24h】

The Role Control Center: Features and Case Studies

机译:角色控制中心:特点和案例研究

获取原文

摘要

Role-based Access Control (RBAC) models have been implemented not only in self-contained resource management products such as DBMSs and Operating Systems but also in a class of products called Enterprise Security Management Systems (ESMS). ESMS products are used for centralized management of authorizations for resources resident in several heterogeneous systems (called target systems) distributed throughout the enterprise. The RBAC model used in an ESMS is called the Enterprise RBAC model (ERBAC). An ERBAC model can be used to specify not only sophisticated access requirements centrally for resources resident in several target systems, but also administrative data required to map those defined access requirements to the access control structures native to the target platforms. However, the ERBAC model (i.e., the RBAC implementation) supported in many commercial ESMS products has not taken full advantage of policy specification capabilities of RBAC. In this paper we describe an implementation of ESMS called the 'Role Control Center' (RCC) that supports an ERBAC model that includes features such as general role hierarchy, static separation of duty constraints, and an advanced permission review facility (as defined in NIST's proposed RBAC standard). We outline the various modules in the RCC architecture and describe how they collectively provide support for authorization administration tasks at the enterprise and target-system levels.
机译:基于角色的访问控制(RBAC)模型不仅在自包含的资源管理产品中实现,例如DBMS和操作系统,而且还在一类名为Enterprise Security Management Systems(ESMS)的产品中。 ESMS产品用于集中管理驻留在整个企业的几种异构系统(称为目标系统)中的资源授权。 ESMS中使用的RBAC模型称为企业RBAC模型(ERBAC)。 erbac模型可用于在居住在多个目标系统中的资源中集中指定复杂的访问要求,还可以在几个目标系统中集中,但也需要将这些定义的访问要求映射到目标平台的访问控制结构所需的管理数据。但是,许多商业ESM产品支持的Erbac模型(即RBAC实施)并未充分利用RBAC的政策规范能力。在本文中,我们描述了一个名为“角色控制中心”(RCC)的ESM的实现,该ESMS支持erbac模型,其中包括常规角色结构,静态责任约束的静态分离,以及高级许可评论设施(如NIST所定义的提出的RBAC标准)。我们概述了RCC架构中的各种模块,并描述了它们如何在企业和目标系统级别中共同提供对授权管理任务的支持。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号