首页> 外文会议> >A model for attribute-based user-role assignment
【24h】

A model for attribute-based user-role assignment

机译:基于属性的用户角色分配模型

获取原文

摘要

The role-based access control (RBAC) model is traditionally used to manually assign users to appropriate roles, based on a specific enterprise policy, thereby authorizing them to use the roles' permissions. In environments where the service-providing enterprise has a huge customer base this task becomes formidable. An appealing solution is to automatically assign users to roles. The central contribution of this paper is to describe a model to dynamically assign users to roles based on a finite set of rules defined by the enterprise. These rules take into consideration the attributes of users and any constraints set forth by the enterprise's security policy. The model also allows dynamic revocation of assigned roles based on conditions specified in the security policy. The model provides a language to express these rules and defines a mechanism to determine seniority among different rules. The paper also shows how to use the model to express mandatory access controls (MAC).
机译:基于角色的访问控制(RBAC)模型传统上用于根据特定的企业策略手动将用户分配给适当的角色,从而授权它们使用角色权限。在服务提供企业具有庞大客户群的环境中,此任务变得突出。一种吸引人的解决方案是自动将用户分配给角色。本文的中央贡献是描述一种模型,用于基于企业定义的有限规则来动态分配用户对角色的角色。这些规则考虑了企业安全策略所提出的用户的属性和任何约束。该模型还允许基于安全策略中指定的条件动态撤销分配的角色。该模型提供了一种表达这些规则的语言,并定义了一种确定不同规则之间资历的机制。本文还展示了如何使用模型来表达强制性访问控制(Mac)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号