摘要
比之传统的访问控制 ,基于角色的访问控制 (RBAC)是一种中性的访问控制策略 ,它可依据具体的系统 ,配置成所需的访问控制机制 ;然而作为 RBAC核心概念的角色却缺少明确的定义和划分方法 .就此提出角色的任务集、权限集、信息集和用户集及其划分方法 .从而为角色的设置和配置提供了某种可行的依据 .
As a neutral access control policy , Role based access control(RBAC) can be configured the needed access control strategy in the case of a real system. But the real RBAC system has' not been realized. One of the important reasons is that the Role, the core concept of RBAC lacks agreement definition and the standard classification. Our contribution in this paper is to lay out four attribute sets of the Role and their classification.