首页> 外文学位 >Framework for role-based delegation models.
【24h】

Framework for role-based delegation models.

机译:基于角色的委派模型的框架。

获取原文
获取原文并翻译 | 示例

摘要

The basic idea behind delegation is that some active entity in a system delegates authority to another active entity in order to carry out some functions on behalf of the former. Delegation can take many forms: human to human, human to machine, machine to machine, and perhaps even machine to human. In this dissertation, I focus on the human to human form of delegation. Specifically, I consider the ability of a user who is a member of a role to delegate his or her role to another user who belongs to some other role. For example, a professor in a university who is also a member in an advising committee role can delegate his/her membership in the advising committee role to another professor who belongs to another committee role. This delegation can take the form of being either permanent or temporary delegation. Moreover, the same professor can delegate only part of his/her professor role (i.e. instructor) to his/her assistant. This delegation can be only temporary.; In this dissertation, I present a comprehensive approach to role-based delegation. More specifically, I identify the characteristics related to delegation, which can be used to develop delegation models; I use a systematic approach to reduce a large number of possible cases to smaller sensible ones; and I formally define and derive some delegation models using roles based on those cases.; The thesis of this research is as follows:; It is possible, by adding a can-delegate relation to the RBAC model in conjunction with constraints, to produce a framework for role-based delegation models. The research approach used to produce a framework for role-based delegation models is an exploratory approach.; In this dissertation, the scope of my work is to address user-to-user delegation based on RBAC96. I use the RBAC96 family of models as the base for my research. I first consider temporary delegation within the framework of RBAC96-Flat-Roles (or RBACO). Then I evolve the model to address other variations of delegation that include delegation based on role hierarchies, permanent delegation, partial delegation, delegation based on the administrator of the actual delegation, and so forth. I also address some issues that deal with revocation. In particular, I consider cascading revocation and grant-independent revocation. I chose this approach in order to work out a simple but useful model in complete detail and then to extend this model gradually to introduce other aspects to add functionality in an incremental manner.; This dissertation shows that by adding a can-delegate relation to the RBAC model in conjunction with constraints, it is possible to produce a framework for role-based delegation models.
机译:委托背后的基本思想是,系统中的某个活动实体将权限委派给另一个活动实体,以代表前者执行某些功能。委托可以采用多种形式:人与人之间,人与机器之间,机器与机器之间,甚至机器与人之间。在本文中,我主要关注人与人之间的授权形式。具体来说,我考虑了作为角色成员的用户将其角色委派给其他角色的能力。例如,大学中同时担任顾问委员会角色的教授可以将其在顾问委员会角色中的成员身份委派给属于另一委员会角色的另一位教授。该授权可以采取永久授权或临时授权的形式。此外,同一位教授只能将其教授角色(即讲师)的一部分委派给他/她的助手。该授权只能是临时的。在本文中,我提出了一种基于角色的委派的综合方法。更具体地说,我确定了与委派相关的特征,这些特征可用于开发委派模型。我使用系统的方法将大量可能的案例减少为较小的明智案例。我根据这些案例使用角色来正式定义和派生一些委托模型。本研究的主题如下:通过将可委托关系与约束一起添加到RBAC模型中,可以为基于角色的委托模型创建框架。用于为基于角色的委托模型建立框架的研究方法是一种探索性方法。在本文中,我的工作范围是解决基于RBAC96的用户到用户委托。我使用RBAC96系列模型作为我研究的基础。我首先考虑在RBAC96-Flat-Roles(或RBACO)框架内进行临时委派。然后,我开发模型以解决其他的委派变化,包括基于角色层次结构的委派,永久委派,部分委派,基于实际委派的管理员的委派等等。我还将解决一些与撤销有关的问题。我特别考虑级联撤销和独立于授予的撤销。我选择这种方法是为了完整详细地构建一个简单但有用的模型,然后逐步扩展该模型以引入其他方面以增量方式添加功能。论文表明,通过在约束条件下为RBAC模型添加可委托关系,可以为基于角色的委托模型提供框架。

著录项

  • 作者

    Barka, Ezedin Salem.;

  • 作者单位

    George Mason University.;

  • 授予单位 George Mason University.;
  • 学科 Engineering System Science.; Information Science.
  • 学位 Ph.D.
  • 年度 2002
  • 页码 101 p.
  • 总页数 101
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 系统科学;信息与知识传播;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号