论文部分内容阅读
针对互联网应用系统平台建设中权限管理和数据访问控制能力不易扩展和重用的局限,结合SAML对NIST-RBAC的统一模型进行了改进,提出以SAML标准实现可移植的信任角色授权的访问控制扩展模型(ExRBAC).利用SAML的可信凭证扩展用户和角色之间的层次,增加角色的信任层次以加强粒度控制,同时设置分层预处理,用于降低处理权限判决点时的复杂性,并结合分层的信任角色扩展了访问认证粒度的动态性.最后以开源门户eXo Platform为实验平台,给出了模型授权流程以及在大型企业门户服务平台应用实例,验证了提出的扩展模型的有效性.
In view of the limitations of authority management and data access control in the construction of Internet application platform, the unified NIST-RBAC model is improved with SAML. An extended access control model based on the SAML standard is proposed (ExRBAC), using SAML’s credible credentials to extend the hierarchy of users and roles, adding the trust hierarchy of roles to enhance granularity control, and setting up hierarchical preprocessing to reduce the complexity of handling authority decision points combined with The hierarchical trust role expands the dynamic of the granularity of access authentication.Finally, by using the open source portal eXo Platform as an experimental platform, the model authorization process and the application example of the large enterprise portal service platform are given, and the validity of the proposed extended model is verified.