计算机集成制造系统 ›› 2014, Vol. 20 ›› Issue (7): 1716-1730.DOI: 10.13196/j.cims.2014.07.dongguanqun.1716.15.20140722

• 产品创新开发技术 • 上一篇    下一篇

面向虚拟企业的PT-TRBAC动态访问控制模型

董冠群1,2,张文芳1,2+,王小敏1   

  1. 1.西南交通大学信息科学与技术学院
    2.西南交通大学信息安全与国家计算网格四川省重点实验室
  • 出版日期:2014-07-30 发布日期:2014-07-30
  • 基金资助:
    国家自然科学基金资助项目(61003245,60903202,61371098);铁道部重大资助项目(2012X004-A,2013X012-A-1,2013X012-A-2);四川省杰出青年学术带头人培育计划资助项目(2011JQ0027);中央高校基本科研业务费专项资助项目(SWJTU12CX099,SWJTU11CX041)。

Project-team and task-role based dynamic access control model for virtual enterprises

  • Online:2014-07-30 Published:2014-07-30
  • Supported by:
    Project supported by the National Natural Science Foundation,China(No.61003245,60903202,61371098),the China Railway Corporation,China(No.2012X004-A,2013X012-A-1,2013X012-A-2),the Outstanding Youth Foundation of Sichuan Province,China(No.2011JQ0027),and the Fundamental Research Funds for Central Universities,China(No.SWJTU12CX099,SWJTU11CX041).

摘要: 在分析虚拟企业访问控制的基本要求以及现有访问控制模型特点的基础上,提出一种基于项目团队和任务角色的高效动态访问控制模型。该模型在无缝集成底层企业级基于角色访问控制模型的基础上,在上层根据任务流程将各盟员企业划分为不同的项目团队,进而实现了基于项目团队和任务角色的分层细粒度动态访问控制。同时,通过定义用户权限更新及撤销算法并引入自动角色指派策略和自动授权策略,实现了虚拟企业工作流系统的动态权限管理,支持虚拟企业中用户—角色和角色—任务—权限的自动指派。

关键词: 虚拟企业, 访问控制, 项目团队, 任务角色, 自动授权

Abstract: Based on analyzing the special requirements of information access control in Virtual Enterprises (VE) and the characteristics of the existing access control models,a high effective dynamic access control model based on Project-Team (PT) and Task-Role (TR) named PT-TR Based Access Control (PT-TRBAC) was proposed.On the premise of seamless integrating the enterprise-level RBAC model,the proposed access control model divided virtual enterprise members into different project teams according to the task flow,by which hierarchical fine-grained project-team-based dynamic access control on public information was realized.Meanwhile,the algorithms to update and revoke users authorities,the automatic role assignment policy and the automatic authorization policy were further given.By these methods,the workflow system could be dynamically managed,and the roles of users could be automatically assigned and authorized in VE.

Key words: virtual enterprise, access control, project team, role-task, automatic authorization

中图分类号: