首页 | 本学科首页   官方微博 | 高级检索  
     

RBAC模型中角色的继承与互斥问题的研究
引用本文:胡金柱,陈娟娟.RBAC模型中角色的继承与互斥问题的研究[J].计算机科学,2003,30(11):160-163.
作者姓名:胡金柱  陈娟娟
作者单位:1. 华中师范大学计算机科学系,武汉,430079
2. 软件工程国家重点实验室,武汉,430072
基金项目:软件工程国家重点实验室开放研究基金(SKL(4)018),湖北省科技攻关项目(2001AA101C31)
摘    要:RBAC (Role-Based Access Control)maps naturally to an organization's structure and facilitates safety administration by separating logically users and permissions via roles as well as constructing role hierarchies, and therefore RBAC offers a powerful means of specifying access control decisions and is attracting increasing attention. In role hierarchies of RBAC,superroles inherit all properties and permissions of subroles. This paper classifies role inheritance into two types : generalization inheritance and supervision inheritance . Furthermore, it outlines two problems in relation to role inheritance :one is how to maintain data integrity,another is how to reduce the effect of absent roles on the normal running of the system. At last ,this paper discusses solutions to them 。RBAC is attracting increasing attention as a security mechanism .Separation of duty is an important safety requirement which is implemented by means of mutual exclusion of roles in RBAC. This paper presents a basic RBAC model,then explores some properties of mutual exclusion of roles,which helps enforcing security policies efficiently. At last ,this paper describes how mutual exclusion of roles affects role hierarchies.

关 键 词:RBAC模型  互斥  角色  继承  问题

Research for Inheritance and Mutual Exclusion of Role in RBAC Model
HU Jin-Zhu CHEN Juan-Juan.Research for Inheritance and Mutual Exclusion of Role in RBAC Model[J].Computer Science,2003,30(11):160-163.
Authors:HU Jin-Zhu CHEN Juan-Juan
Abstract:RBAC (Role-Based Access Control) maps naturally to an organization's structure and facilitates safety administration by separating logically users and permissions via roles as well as constructing role hierarchies, and therefore RBAC offers a powerful means of specifying access control decisions and is attracting increasing attention. In role hierarchies of RBAC, superroles inherit all properties and permissions of subroles. This paper classifies role inheritance into two types : generalization inheritance and supervision inheritance . Furthermore, it outlines two problems in relation to role inheritance: one is how to maintain data integrity,another is how to reduce the effect of absent roles on the normal running of the system . At last,this paper discusses solutions to them . RBAC is attracting increasing attention as a security mechanism . Separation of duty is an important safety requirement which is implemented by means of mutual exclusion of roles in RBAC . This paper presents a basic RBAC model,then explores some properties of mutual exclusion of roles,which helps enforcing security policies efficiently. At last,this paper describes how mutual exclusion of roles affects role hierarchies.
Keywords:RBAC  Role inheritance  Mutual exclusion of roles  Role hierarchy  Separation of duty  
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机科学》浏览原始摘要信息
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号