摘要
针对大型企业信息系统在访问控制和安全管理方面的复杂性,传统的访问控制策略不适应大型企业信息系统在安全方面的要求。对角色的访问控制(RBAC)模型进行详细的分析,针对RBAC的不足提出改进的IRBAC模型,并将它应用到企业信息系统的设计中,建立企业的安全访问控制策略。采用IRBAC模型的访问控制策略简化了角色层次结构,方便了角色授权。
Aiming at the complication of access control andinforrnation management on enterprise information system, the traditional access control policy doesn't adapt secure requirements of it. On analyzing the role based access control (RBAC) model,a new improved role based access control (IRBAC) is proposed and is applied in designing of enterprise information system. The policy of access control is built for enterprise information system. The application of IRBAC model makes the structure of role hierarchical to be simplified. It is convenient for role authorization.
出处
《计算机技术与发展》
2007年第2期42-45,共4页
Computer Technology and Development
基金
陕西省自然科学基金(2001X30)