• 论文 •    

应用服务提供商模式下的系统访问控制模型

刘强,陈新,陈新度   

  1. 广东工业大学 机电学院CIMS重点实验室,广东广州510075
  • 出版日期:2008-02-15 发布日期:2008-02-25

Access control model of application service provider system

LIU Qiang, CHEN Xin, CHEN Xin-du   

  1. Key Lab of CIMS, School of Mechatronics, Guangdong University of Technology, Guangzhou 510075, China
  • Online:2008-02-15 Published:2008-02-25

摘要: 针对应用服务提供商系统的结构特点,分析了应用服务提供商系统的访问控制权限管理的需求,基于角色的访问控制模型和相关技术,引入全局角色的概念,使用域标签技术,设计了“1+n”管理格局的应用服务提供商系统访问控制模型,并使用ARBAC97中定义的指派函数来表征应用服务提供商-基于角色的访问控制模型的初始化授权策略和上层授权策略。该模型可以实现各个逻辑子系统的细粒度权限管理,亦可以实现各子系统功能差异化配置。以应用服务提供商模式的产品信息服务系统的访问控制权限管理为例,说明了应用服务提供商-基于角色的访问控制的应用方式。

关键词: 应用服务提供商, 基于角色的访问控制, 授权策略, 权限管理

Abstract: Aiming at the structure characteristics of Application Service Provider (ASP) system, management requirements for access control in ASP system were analyzed. To meet those requirements, an access control model named ASP-RBAC, which presenting ′1+n′ layout, was designed and developed based on the Role Based Access Control (RBAC) model and techniques. In this model, the conception of globe role was imported to realize the uniform supervision of the roles , and the technique of domain label was utilized to execute the domain distinguishing. Also, the authority policies of top management lay and system initialization was formalized by the assignment function of ARBAC97. ASP-RBAC not only realized the fine-granularity access control in sub-logic-system but also realized different function configuration among those sub-logic-systems. Access control model of ASP-PISP was provided to illustrate the application of ASP-RBAC.

Key words: application service provider, role based access control, authority policy, authority management

中图分类号: