首页> 外文期刊>Concurrency and Computation >A role-based infrastructure management system: design and implementation
【24h】

A role-based infrastructure management system: design and implementation

机译:基于角色的基础架构管理系统:设计和实现

获取原文
获取原文并翻译 | 示例

摘要

Over the last decade there has been a tremendous advance in the theory and practice of role-based access control (RBAC). One of the most significant aspects of RBAC can be viewed from its management of permissions on the basis of roles rather than individual users. Consequently, it reduces administrative costs and potential errors. The management of roles in various RBAC implementations, however, tends to be conducted on an ad hoc basis, closely coupled with a certain context of system environments. This paper discusses the development of a system whose purpose is to help manage a valid set of roles with assigned users and permissions for role-based authorization infrastructures. We have designed and implemented the system, called RolePartner. This system enables role administrators to build and configure various components of a RBAC model so as to embody organizational access control policies which can be separated from different enforcement mechanisms. Hence the system helps make it possible to lay a foundation for role-based authorization infrastructures. Three methodological constituents are introduced for our purposes, together with the design and implementation issues. The system has a role-centric view for easily managing constrained and hierarchical roles as well as assigned users and permissions. An LDAP-accessible directory service was used for a role database. We show that the system can be seamlessly integrated with an existing privilege-based authorization infrastructure.
机译:在过去的十年中,基于角色的访问控制(RBAC)的理论和实践取得了巨大的进步。从基于角色而不是单个用户的权限管理可以看出RBAC的最重要方面之一。因此,它减少了管理成本和潜在的错误。但是,各种RBAC实现中的角色管理往往是在临时的基础上进行的,并与系统环境的特定上下文紧密结合。本文讨论了系统的开发,该系统的目的是帮助管理具有有效角色集的用户,并为其分配基于角色的授权基础结构的权限。我们已经设计并实现了名为RolePartner的系统。该系统使角色管理员可以构建和配置RBAC模型的各个组件,以体现可以与不同执行机制分开的组织访问控制策略。因此,该系统有助于为基于角色的授权基础结构奠定基础。为了我们的目的,介绍了三种方法学组成部分,以及设计和实施问题。该系统具有以角色为中心的视图,可轻松管理受约束和分层的角色以及分配的用户和权限。 LDAP可访问的目录服务用于角色数据库。我们展示了该系统可以与现有的基于特权的授权基础结构无缝集成。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号