首页> 外文会议>Proceedings of the Third IASTED International Conference on Advances in Computer Science and Technology >ADVANCED AUTONOMOUS ACCESS CONTROL SYSTEM FOR WEB-BASED SERVER APPLICATIONS
【24h】

ADVANCED AUTONOMOUS ACCESS CONTROL SYSTEM FOR WEB-BASED SERVER APPLICATIONS

机译:基于Web的服务器应用程序的高级自治访问控制系统

获取原文
获取原文并翻译 | 示例

摘要

The number of the server applications in the world is rapidly increasing. Many of them need to handle user access. A typical approach is to implement access control logic directly into an object which is responsible for storing and retrieving the data and performing required operations over the data. The object checks access to appropriate methods and permits or denies required operation. But the systems are usually constructed from many such objects which require similar access control system. This leads to a greater overhead because access control checking must be coded inside all those objects.More code brings more bugs into the system moreover if a programmer simply forgets to verify some of required rights in the code then the system may encounter a forbidden data access. This article deals with that problem area and designs a unified database layer operating over relation database management systems. Key benefits it brings are strong simplification of the access control system from the point of view of the application code and impossibility to access data without permissions.
机译:全球服务器应用程序的数量正在迅速增加。其中许多需要处理用户访问。一种典型的方法是将访问控制逻辑直接实现到一个对象中,该对象负责存储和检索数据以及对数据执行所需的操作。该对象检查对适当方法的访问,并允许或拒绝所需的操作。但是系统通常是由许多需要类似访问控制系统的对象构成的。这将导致更大的开销,因为访问控制检查必须在所有这些对象中进行编码。更多的代码会给系统带来更多的错误,而且如果程序员只是忘记验证代码中的某些必需权限,那么系统可能会遇到禁止的数据访问。本文讨论了该问题领域,并设计了在关系数据库管理系统上运行的统一数据库层。从应用程序代码的角度来看,它带来的主要好处是极大地简化了访问控制系统,并且没有权限也无法访问数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号