【24h】

PBDM: A Flexible Delegation Model in RBAC

机译:PBDM:RBAC的灵活委派模型

获取原文

摘要

Role-based access control (RBAC) is recognized as an efficient access control model for large organizations. Most organizations have some business rules related to access control policy. Delegation of authority is among these rules. RBDMO and RDM2000 models are recently published models for role-based delegation. They deal with user-to-user delegation. The unit of delegation in them is a role. But in many cases users may want to delegate a piece of permission from a role. This paper proposes a flexible delegation model named Permission-based Delegation Model (PBDM), which is built on the well-known RBAC96 model. PBDM supports user-to-user and role-to-role delegations with features of multi-step delegation and multi-option revocation. It also supports both role and permission level delegation, which provides great flexibility in authority management. In PBDM, a security administrator specify the permissions that a user (delegator) has authority to delegate to others (delegatee), then the delegator creates one or more temporary delegation roles and assigns delegatees to particular roles. This gives us clear separation of security administration and delegation.
机译:基于角色的访问控制(RBAC)被识别为大型组织的有效访问控制模型。大多数组织都有一些与访问控制策略相关的业务规则。权力代表团是这些规则之一。 RBDMO和RDM2000型号最近发布了基于角色的委派的模型。他们处理用户到用户委派。委派的单位是一个角色。但在许多情况下,用户可能希望委派一个权限的角色。本文提出了一个名为基于权限的委派委派模型(PBDM)的灵活委派委派模型,该模型构建在众所周知的RBAC96模型上。 PBDM支持用户到用户和角色与角色委托,具有多步委派和多项选项撤销的功能。它还支持角色和权限级别代表团,这提供了极大的权威管理灵活性。在PBDM中,安全管理员指定用户(委托)对委托给别的权限(Delegatee)的权限,然后摘录器创建一个或多个临时委托角色,并将委托将委托分配给特定的角色。这让我们明确分离安全管理和代表团。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号