机构地区: 佛山科学技术学院
出 处: 《计算机工程与应用》 2010年第33期132-138,共7页
摘 要: 提出了一种角色访问控制扩展模型,该模型在标准RBAC体系中引入分级策略,通过扩展读写规则和授权限制消除了RBAC中向下的信息流,并通过范围分离和会话密级等语义保留了标准RBAC的灵活性和表达力。该模型可应用在众多既需要控制信息流动的强制存取控制又需要有角色存取机制灵活性的系统中。在给出模型的形式化定义后,对模型的实现规则、访问策略、权限分配管理、在多级关系数据库中的实现机制及模型的BNF范式以及具体应用做了说明。 An extended model of role based access control is proposed,which introduces classified policy into standard RBAC. The model erases the downward information flow by extended rules of read and write and some authorization constraints, and keeps the expressive power and flexibility of the standard RBAC by semantics of separation of category relations and session classes.The model can be used in the information systems that need not only the MAC to control the information flow but also the flexibility of the RABC.After a formal definition of the model, the implementation rules, access decision policies, management of authorization distribution, implement mechanism in multilevel relational database, BNF notations and application of the model are also discussed.
领 域: [自动化与计算机技术] [自动化与计算机技术]