Scalable Access Control Model Based on Double-tier Role and Organization
-
摘要: 针对现有基于角色的访问控制(RBAC)研究存在角色设置单一使得适应性差、多域环境下角色或权限冗余、对资源管理关注不够等问题,论文提出支持资源管理的基于双层角色和组织的访问控制模型。通过双层角色划分,提出基于职能角色和任务角色的双层角色架构,使得模型更加符合实际,也更具适应性;引入组织的概念并与双层角色相结合,对角色和权限的概念加以扩展,形式化定义了提出的基于双层角色和组织的访问控制模型,描述了影响模型安全的职责分离约束和势约束。对模型的表达能力、复杂度进行了分析,分析表明该机制不仅保留了RBAC的特点与优势,且比RBAC具有较低的复杂度并更适合于由多个相似组织构成的分布式多域环境。Abstract: For tackling the deficiencies of weak adaptability due to the singleness of the role establishment method, role or privilege redundancy, and little attention on resource management in the existing Role-Based Access Control (RBAC) researches, a Scalable Access Control model Based on Double-Tier Role and Organization (SDTR-OBAC) is proposed. Through double role partition, a double-tier role architecture of function role and task role is presented, solving the problem that the traditional role can not cover the requirements of both organizational level and application level at the same time. The concept of organization is introduced to integrate with the double-tier role and form an organization-role pair assigned to user instead of role only in RBAC, making model suitable to cross-domain access as well as a single domain. Through extending privileges as an operation and resource type pair, the model and its constraints including separation of duty and cardinality constraint are defined formally. The discussion of expressive power and complexity indicates that SDTR-OBAC retains all the advantages of RBAC, and can effectively reduce the administration complexity with better scalability and universality.
期刊类型引用(10)
1. 赵大燕,何华均,李宇平,张钧波,李天瑞,郑宇. 面向政务协同的访问控制模型. 计算机应用. 2025(01): 162-169 . 百度学术
2. 熊天虹,余阳,娄定俊. 工作流系统中的PRBAC访问控制模型研究. 应用科学学报. 2020(05): 672-681 . 百度学术
3. 李应琪,王位杰,檀庭方. 基于属性管控的RBAC模型权限管理设计. 自动化应用. 2020(10): 68-69+74 . 百度学术
4. 罗黎明,朱丽霞,曹越峰,王琪,肖金超. 基于人工智能技术的电力信息系统访问自动控制模型. 自动化与仪器仪表. 2020(12): 42-45 . 百度学术
5. 李龙,古天龙,常亮,李晶晶,钱俊彦. 云制造中策略可更新的去中心化访问控制机制. 计算机集成制造系统. 2019(09): 2280-2290 . 百度学术
6. 林曦,韩益亮. 基于属性加密的共享文件分级访问控制方案. 燕山大学学报. 2017(05): 450-456 . 百度学术
7. 刘浩,陈志刚,张连明. P2P网络中基于准入度的任务访问控制模型. 信息网络安全. 2017(06): 22-29 . 百度学术
8. 苏玮,尹晓. 智慧社区中的跨域访问控制模型研究. 智能建筑与智慧城市. 2016(11): 64-68 . 百度学术
9. 李莉,史国振,王璇,慈云飞. 共享文件加密存储分级访问控制方案的实现. 网络与信息安全学报. 2016(07): 26-32 . 百度学术
10. 陈志锋,李清宝,张平,曾光裕. 基于访问控制的Hypervisor非控制数据完整性保护. 电子与信息学报. 2015(10): 2508-2516 . 本站查看
其他类型引用(10)
-
计量
- 文章访问数: 1119
- HTML全文浏览量: 178
- PDF下载量: 615
- 被引次数: 20