首页> 外国专利> Method and system of access control based on a constraint controlling role assumption

Method and system of access control based on a constraint controlling role assumption

机译:基于约束控制角色假设的访问控制方法和系统

摘要

In an RBAC system, a capability is defined as including an operation and an object on which the operation is to be performed. The capability is assigned to a role, which is in turn assigned to a user. Whether a user's request to perform an operation on an object should be authorized is determined based on whether a capability to perform the operation on the object is assigned to a role which is in turn assigned to the user. Further, the authorization is determined based on the evaluation of the constraint(s) attached to the role. If the evaluation result of the constraint(s) disallows the user to assume the role, the user is prohibited from performing the operation on the object even the user has such capability.
机译:在RBAC系统中,能力被定义为包括操作和要在其上执行操作的对象。该功能分配给一个角色,该角色又分配给用户。基于是否应将对对象执行操作的请求的权限确定为是否将对对象执行操作的能力分配给角色,该角色又被分配给用户。此外,基于对角色所附加约束的评估来确定授权。如果约束的评估结果不允许用户承担角色,则即使用户具有这种能力,也禁止用户对对象执行操作。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号