检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:朱一群[1]
出 处:《计算机应用与软件》2015年第7期35-38,共4页Computer Applications and Software
基 金:国家青年自然科学基金项目(61201258);上海市教委科研创新项目(12AZ05)
摘 要:在角色访问控制的基础上,提出本域角色表和外域角色表的概念,引入域间信任度,提出一种基于用户信任的多域访问控制模型——UT-MDAC。UT-MDAC模型通过不同域之间的信任度,获得用户访问外域的资格,并通过用户的信任值,判断用户的行为可信性。结合域间信任度和外域角色表,系统分配用户外域角色,用户根据外域角色对应的权限,对外域资源信息进行实际访问操作。给出UT-MDAC模型的定义和授权机制,访问控制流程,并给出模型的实际应用分析,比较分析模型的性能和安全性。分析结果表明该模型能实现动态授权,且满足最小特权原则,具有普遍适用性。On the basis of Role-based Access Control ( RBAC), this paper presents local domain role and foreign domain role, and introduces inter domain trust, presents a user trust based multi-domain access control model (UT-MDAC). The UT-MDAC model can get users access qualification to foreign domain according to inter domain trust, and can judge the user behavior trust by user trust value. System assigns user foreign domain role according to inter domain trust and table of foreign domain role, and user accesses foreign domain resource information according to permission. The paper presents the definition and authorization mechanism of UT-MDAC model and access control process. It also gives an application example of the model to compare and analyze its performance and safety. The analysis results show that the model can grant authorization dynamically and meet minor privilege principle, and it has universal practicability.
分 类 号:TP3[自动化与计算机技术—计算机科学与技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.3