论文部分内容阅读
随着信息系统复杂性不断增强,许多大型应用系统都具有动态性,但是传统的访问控制机制不能提供动态权限分配。该文提出一个实现动态安全策略的访问控制模型,在RBAC模型基础上通过代理动态地决定访问权限,代理根据抽象角色定义和上下文信息规则,通过推导模块得到用户的实际角色,阐述模型的组成并将它应用于一个项目管理系统中。结果表明,该模型比传统的访问控制模型更加高效安全。
As the complexity of information systems continues to grow, many large-scale application systems are dynamic, but traditional access control mechanisms do not provide dynamic rights assignment. In this paper, an access control model to achieve dynamic security policy is proposed. Based on the RBAC model, the access rights are dynamically determined through the proxy. The agent obtains the user’s actual role through the derivation module according to the abstract role definition and the context information rules. Apply it to a project management system. The result shows that this model is more efficient and safer than the traditional access control model.