首页> 外文期刊>Computer and Information Science >Formal Description for an Object-Oriented Role-based Access Control Model
【24h】

Formal Description for an Object-Oriented Role-based Access Control Model

机译:面向对象的基于角色的访问控制模型的形式描述

获取原文
       

摘要

Role-based access control(RBAC) is a promising technology for managing and enforcing security in large-scale enterprise-wide system, and we were motivated by the need to manage and enforce the strong access control technology of RBAC in large-scale Web environments. Majority of traditional access control models were passive data-protections, which were not suitable for large and complex multi-user interactive applications. In this paper, we develop a general model to control users’ behaviors based on their roles actively, and proposes a framework of well-defined Formal Description for developers to build application-level access control based on users’ roles. It ensure that each role is configured with consistent privileges, each actor is authorized to proper roles and then each actor can activate and play his authorized roles without interest conflicts. These formal specifications are consistent and inferable, complete and simplified, abundant and scalable for diversified multi-user applications.
机译:基于角色的访问控制(RBAC)是一种用于在大型企业级系统中管理和实施安全性的有前途的技术,我们受到在大型Web环境中管理和执行RBAC的强大访问控制技术的需求的激励。传统访问控制模型的大多数是被动数据保护,不适用于大型和复杂的多用户交互应用程序。在本文中,我们开发了一个通用模型来主动基于用户的角色来控制用户的行为,并为开发人员提出了定义明确的形式描述框架,以供开发人员基于用户的角色构建应用程序级访问控制。它确保每个角色都配置有一致的特权,每个角色都被授予适当的角色,然后每个角色可以激活并扮演其授权角色而不会引起利益冲突。这些形式规范对于各种多用户应用程序是一致且可推断的,完整且简化的,丰富且可扩展的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号