• 论文 •    

面向产品生命周期管理的多粒度访问控制模型

耿俊浩,张振明,田锡天,张定华   

  1. 1.西北工业大学 CAPP与制造工程软件研究所,陕西西安710072;2.西北工业大学 现代设计与集成制造技术教育部重点实验室,陕西西安710072
  • 出版日期:2008-11-15 发布日期:2008-11-25

PLM-oriented multi-granular access control model

GENG Jun-hao, ZHANG Zhen-ming, TIAN Xi-tian, ZHANG Ding-hua   

  1. 1.Institute of CAPP & Manufacturing Engineering Software, Northwestern Polytechnical University, Xian 710072, China;2.Ministry of Education Key Lab of Contemporary Design and Integrated Manufacturing Technology,Northwestern Polytechnical University, Xi'an 710072, China
  • Online:2008-11-15 Published:2008-11-25

摘要: 为满足复杂应用环境下产品生命周期管理系统的访问控制需求,提出一种面向产品生命周期管理的多粒度访问控制模型。该模型通过完善基于角色的访问控制方法中访问主体的组成粒度和访问客体的层次粒度,引入访问客体生命周期粒度和许可分配控制粒度,在扩大基于角色的访问控制范围的同时,一定程度上降低了误授权率和公共许可的重复授权量,实现了对不同层次和生命周期状态的访问客体的精确控制,解决了临时授权、项目授权、委托授权等导致的许可一致性控制问题。最后,给出了该模型的形式化描述和许可一致性控制算法,并通过实例验证了该模型的有效性。

关键词: 访问控制, 产品生命周期管理, 粒度, 基于角色的访问控制

Abstract: To meet the access control requirements of Product Lifecycle Management (PLM) system in complicated application circumstances, PLM-oriented Multi-granular Access Control (PLM MAC) model was proposed based on Role-Based Access Control (RBAC) standard. Access subject composition granularities and access object hierarchical granularities from RBAC model were improved in this model; access object lifecycle granularities and permission assignment control granularities were introduced into PLM MAC model. While the control scope of RBAC model was extended in PLM MAC, it reduced the probability of authorization mistakes and the quantity of repeated public authorization; it implemented the precise control for various access objects in all levels and all lifecycle states; and it resolved the permission coherence control induced by temporary authorization, project authorization and delegation authorization. At last, a formal description of PLM MAC model as well as an algorithm of permission consistency control were presented, and an application example was provided to verify the effectiveness of PLM MAC method.

Key words: access control, product lifecycle management, granularity, role-based access control

中图分类号: