论文部分内容阅读
在基于角色访问控制模型的基础上,针对U型组织结构中信息系统的特点,提出一个扩展角色访问控制模型,新模型引入信息域和操作域的概念,对角色和权限进行扩展和形式化定义,使扩展RBAC模型对于信息系统的权限分配直观、容易理解、便于使用,能够灵活、高效地对系统进行权限访问控制,并采用客户端自主访问控制和服务器端审核的方式,增强访问控制安全。
Based on the role-based access control model, this paper proposes an extended role access control model based on the characteristics of information system in the U-shaped organizational structure. The new model introduces the concept of information domain and operation domain, and expands and formalizes the roles and permissions , The extended RBAC model is intuitive, easy to understand and easy to use for assigning the authority of the information system. It can flexibly and efficiently control access to the system and enhance the access control security by adopting the methods of client independent access control and server-side auditing.