摘要
针对基于角色的访问控制模型RBAC没有将上下文考虑在内,而且控制力度只能到达商务方法级,提出了一种基于规则引擎的访问控制模型。该模型不仅继承了RBAC的优点,同时还利用规则实现了细粒度的访问控制,使开发人员能够动态地控制应用程序的行为。
According to Role-Based Access Control(RBAC) dose not take into account the context,and control efforts can only reach the business method level,Proposed a access control based on rule engine.The model not only inherits the advantages of RBAC,but also use the rules to achieve the fine-grained access control,enabling developers to dynamically control the behavior of the application.
出处
《计算机安全》
2011年第6期37-39,共3页
Network & Computer Security