• 论文 •    

基于受控对象的多主体访问控制模型

李长城,刘成颖,洪名松,蔡   

  1. 1.清华大学 精密仪器与机械学系,北京 100084;2.辽宁工程技术大学 机械工程学院,辽宁 阜新 123000
  • 出版日期:2005-03-15 发布日期:2005-03-25

Object-based multi-subject access control model

LI Chang-cheng,LIU Cheng-ying,HONG Ming-song,CAI Wei   

  1. 1.Dep. of Precision Instruments & Mechanics,Tsinghua Univ., Beijing 100084, China;2.Sch. of Mechanical Eng., Liaoning Technical Univ., Fuxin 123000, China
  • Online:2005-03-15 Published:2005-03-25

摘要: 在研究和分析基于角色的访问控制模型、基于组的访问控制模型等的基础上,结合工艺信息管理的特点,提出了基于受控对象的多主体访问控制模型。该模型能够利用受控对象之间的继承关系对访问控制策略进行继承,同时将访问控制的主体扩展为多种,实现针对单个用户和对象实例的细粒度的访问控制,具有授权操作简单、高效和易于表达的特点。该模型在进行权限控制时考虑了执行的上下文环境,是一种动态访问控制模型。最后给出了一个应用实例。

关键词: 访问控制, 工艺信息管理, 基于受控对象, 动态安全模型

Abstract: Based on study of the role-based access control (RBAC) model and the team-based access control (TMAC) model, combined with the characteristics of the technological process information management, an object-based multi-subject access control model was proposed. In this model, objects access control strategy could be inherited through the objects inheritance hierarchies and the type of access subject was expanded to more types. The model implemented a fine-grained security administration at the level of individual users and individual objects. And the access permissions were assigned effectively and were easy to be expressed. As an active security model, it considered the context of objects and users when activating the permissions. Finally, an application example was introduced to prove the feasibility and advantages of this model.

Key words: access control, process information management, object-based, active security model

中图分类号: