首页> 外文期刊>International Journal of Information Security >Delegation in role-based access control
【24h】

Delegation in role-based access control

机译:基于角色的访问控制中的委派

获取原文
获取原文并翻译 | 示例
           

摘要

User delegation is a mechanism for assigning access rights available to one user to another user. A delegation can either be a grant or transfer operation. Existing work on delegation in the context of role-based access control models has extensively studied grant delegations, but transfer delegations have largely been ignored. This is largely because enforcing transfer delegation policies is more complex than grant delegation policies. This paper, primarily, studies transfer delegations for role-based access control models. We also include grant delegations in our model for completeness. We present various mechanisms that authorize delegations in our model. In particular, we show that the use of administrative scope for authorizing delegations is more efficient than using relations. We also discuss the enforcement and revocation of delegations. Finally, we study delegation in the context of workflow systems. In particular, we demonstrate the application of the administrative scope and administrative domain concepts to control delegation of tasks in worklist-based workflow systems.
机译:用户委派是一种将一个用户可用的访问权限分配给另一用户的机制。委派可以是授予操作或转移操作。在基于角色的访问控制模型中,有关委派的现有工作已经广泛研究了授权委派,但是转移委派在很大程度上被忽略了。这主要是因为强制执行传输委派策略比授予委派策略更为复杂。本文主要研究基于角色的访问控制模型的传输委派。为了完整性,我们还将赠款委托包括在我们的模型中。我们介绍了各种授权模型的机制。特别是,我们表明,使用行政范围来授权代表团比使用关系更有效。我们还将讨论代表团的执行和撤销。最后,我们在工作流系统的上下文中研究委托。特别是,我们演示了管理范围和管理域概念在控制基于工作列表的工作流系统中的任务委派方面的应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号