【24h】

A FORMAL MODEL FOR PARAMETERIZED ROLE-BASED ACCESS CONTROL

机译:基于角色的访问控制的正式模型

获取原文

摘要

Role-Based Access Control (RBAC) usually enables a higher level view of authorization. In this model, access permissions are assigned to roles and, in turn, roles are allocated to subjects. The usefulness of the RBAC model is well documented. It includes simplicity, consistency, scalability and ease of manageability. In practice, however, only limited versions of RBAC seem to have been successfully implemented, notably in applications such as databases and operating systems. The problem stems from the fact that most applications require a finer degree of authorization than what core RBAC models are able to provide. In theory, current RBAC models can be adapted to capture fine grained authorizations by dramatically increasing the number of distinct roles in these models. However, this solution comes at an unacceptably high cost of allocating low level privileges which eliminates the major benefits gained from having a high level RBAC model. This paper presents a methodology for refining abstract RBAC models into new Parameterized RBAC models which provide finer grain of authorizations. The semantics of the Parameterized RBAC model is given as a state-based core RBAC model expressed in the formal specification notation Z. By systematically applying this methodology the scope of applications of RBAC is substantially extended and the major benefits of having the core model are maintained.
机译:基于角色的访问控制(RBAC)通常可以实现更高级别的授权视图。在此模型中,访问权限分配给角色,又将角色分配给受试者。 RBAC模型的有用性记录了很好。它包括简单性,一致性,可扩展性和可管理性。然而,在实践中,只有有限的RBAC版本似乎已经成功实现,特别是在数据库和操作系统等应用程序中。问题源于大多数应用需要比核心RBAC模型能够提供的更精细的授权。理论上,目前的RBAC模型可以通过大大增加这些模型中的不同角色的数量来捕获细粒度授权。然而,该解决方案以不可接受的高成本分配低级特权,这消除了具有高水平RBAC模型所获得的主要益处。本文介绍了一种将摘要RBAC模型精炼成新的参数化RBAC模型的方法,该模型提供更精细的授权。参数化RBAC模型的语义作为正式规格符号Z中表达的基于状态的核心RBAC模型。通过系统地应用这种方法,RBAC的应用范围基本上延伸,保持了核心模型的主要益处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号