摘要
为将角色访问控制RBAC应用于分布式环境,本文研究了传统RBAC角色组织结构,在倒转树型角色组织结构的基础上引入域的概念,将分布式系统中各机构封装成域.进而针对分布式系统的特殊性提出原始域和构造域概念,扩展了权限的概念,然后分别提出了域内和域间的访问控制策略.从而实现了RBAC的分散化和分布式管理.
In order to apply the role-based access control into distributed environment, this article did a lot of research on the role architecture of the traditional RBAC, introduced the concept of domain on the basis of the inverted tree architecture, encapsulated each part of the distributed system into domains, and put forward the concepts of origin-domain and constructed-domain according to the particularity of the distributed system, expended the concept of Permission at the same time, then bring forward two different policies separately for the access control in one domain and inter-domains access control, consequently, realized the disperse and distributed organization of RBAC.
出处
《四川大学学报(自然科学版)》
CAS
CSCD
北大核心
2007年第2期303-306,共4页
Journal of Sichuan University(Natural Science Edition)
关键词
基于角色的访问控制
分布式信息系统
原始域
构造域
role-based access control, distributed irrformation system, origin-domain, constructed-domain