摘要
介绍了基于角色的安全访问控制 (RBAC)基本模型 ,并根据管理信息系统特点 ,对模型进行了改进 ,为操作许可P定义一关于环境参数的布尔函数fp ,增强了RBAC基本模型的控制粒度 .同时 ,引入先决操作许可概念 ,有效地防止由于操作许可设置不当 ,而导致的已授权操作许可无法执行的现象 .并给出了应用实例 .
This paper introduces Role Based Access Control(RBAC) model, and presents an improved model based on the characteristic of MIS to define an environment function fp to enhance access control granularity of RBAC model. In addition the concept of prerequisite permission is introduced for preventing improper authorization causing non excution of authorized permission. Finally, an application of this improved model is given.
出处
《南京师范大学学报(工程技术版)》
CAS
2003年第4期41-44,共4页
Journal of Nanjing Normal University(Engineering and Technology Edition)