首页> 中文期刊>计算机工程 >一种基于T-RBAC的访问控制改进模型

一种基于T-RBAC的访问控制改进模型

     

摘要

针对T-RBAC在权限控制及职责分离上存在的不足,提出一种改进模型.新模型简化T-RBAC模型的任务分类,为任务加入任务上下文及任务状态属性,使权限的授予与任务上下文、任务状态紧密联系,增强对权限的动态管理.利用私有角色解决互斥权限在继承过程中可能产生的权限共享问题.使用历史记录保证任务执行过程中的动态职责分离.该模型提供了更细粒度的权限管理,能更好地满足职责分离和最小特权原则.%Because of the shortcoming of permission control and separation of duties in T-RBAC, an improved model is proposed. New model simplifies the task classification of T-RBAC, adds context and state property to task, and builds a close relationship between permissions granting and the task context and state property, which enhances the dynamic management of permissions. It also solves the problem of mutually exclusive rights possessed by one role while inherited in roles hierarchy using private roles, and ensures the dynamic separation of duties by checking the history of task performance. New model provides a better permissions management, and better meets the separation of duties and least privilege principles.

著录项

相似文献

  • 中文文献
  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号