摘要
介绍和分析了2种主流访问控制技术——基于角色的访问控制及基于任务的访问控制。针对现有模型的不足,结合某分布式系统的复杂访问控制需求和处理特点,建立了基于任务—角色的访问控制TRBAC模型,阐述了模型对最小权限原则、权限分离原则、角色层次关系的支持。
The characteristic and applicability spectrum of some recent models such as DAC, MAC, RBAC and TBAC was demonstrated. Access control requirement in a certain distributed control system was analyzed in detail. To the deficiency of the exiting models, in order to improve the security and practicability of the distributed control system, a new type model, TRBAC (task-role based access control) model was built .The configuration and characteristic of the model was described. The support of least privilege, separation of duties, data abstraction and role hierarchies in the model were explained.
出处
《海军航空工程学院学报》
2010年第4期406-410,共5页
Journal of Naval Aeronautical and Astronautical University