首页 | 本学科首页   官方微博 | 高级检索  
     

面向多级关系数据库的RBAC扩展模型
引用本文:钟勇,郭伟刚,钟昌乐.面向多级关系数据库的RBAC扩展模型[J].计算机工程与应用,2010,46(33):132-138.
作者姓名:钟勇  郭伟刚  钟昌乐
作者单位:1.佛山科学技术学院 信息与教育技术中心,广东 佛山 528000 2.南京理工大学 计算机科学与技术博士后流动站,南京 210094
基金项目:中国博士后科学基金,广东省自然科学基金,江苏省博士后科研资助计划,佛山市科技发展专项资金 
摘    要:提出了一种角色访问控制扩展模型,该模型在标准RBAC体系中引入分级策略,通过扩展读写规则和授权限制消除了RBAC中向下的信息流,并通过范围分离和会话密级等语义保留了标准RBAC的灵活性和表达力。该模型可应用在众多既需要控制信息流动的强制存取控制又需要有角色存取机制灵活性的系统中。在给出模型的形式化定义后,对模型的实现规则、访问策略、权限分配管理、在多级关系数据库中的实现机制及模型的BNF范式以及具体应用做了说明。

关 键 词:角色访问控制  强制访问控制  多级关系数据库  
收稿时间:2009-4-2
修稿时间:2009-6-22  

Extended RBAC model for multilevel relational database
ZHONG Yong,GUO Wei-gang,ZHONG Chang-le.Extended RBAC model for multilevel relational database[J].Computer Engineering and Applications,2010,46(33):132-138.
Authors:ZHONG Yong  GUO Wei-gang  ZHONG Chang-le
Affiliation:1.Information and Educational Technology Center,Foshan University,Foshan,Guangdong 528000,China 2.Postdoctoral Mobile on Computer Application,Nanjing University of Science and Technology,Nanjing 210094,China
Abstract:An extended model of role based access control is proposed,which introduces classified policy into standard RBAC. The model erases the downward information flow by extended rules of read and write and some authorization constraints, and keeps the expressive power and flexibility of the standard RBAC by semantics of separation of category relations and session classes.The model can be used in the information systems that need not only the MAC to control the information flow but also the flexibility of the RABC.After a formal definition of the model, the implementation rules, access decision policies, management of authorization distribution, implement mechanism in multilevel relational database, BNF notations and application of the model are also discussed.
Keywords:role based access control  mandatory access control  multilevel relational database
本文献已被 维普 万方数据 等数据库收录!
点击此处可从《计算机工程与应用》浏览原始摘要信息
点击此处可从《计算机工程与应用》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号