首页> 美国政府科技报告 >Secure Enterprise Access Control (SEAC) Role Based Access Control (RBAC)
【24h】

Secure Enterprise Access Control (SEAC) Role Based Access Control (RBAC)

机译:安全企业访问控制(sEaC)基于角色的访问控制(RBaC)

获取原文

摘要

Access to resources such as applications and web services are becoming increasingly difficult to manage via access control lists (ACLs). ACLs usually consist of a client's name or unique identifier. However, resource access is usually based on client characteristics such as command assignments, clearances, and/or pay grade. If a user is reassigned, changes clearance, or is promoted, access to resources should also change. Instead, with ACLs, resource managers constantly have to evaluate personnel records to determine resource access. Such a task can become overwhelming as the number of personnel within an organization grows. Limited access to personnel records by resource managers could compound the problem. This paper discusses a government off-the-shelf- solution (GOTS) for Secured Enterprise Access Control (SEAC) Role-Based Access Control (RBAC) proposed by Richard Fernandez, Space and Naval Warfare Systems Center, San Diego (SSC San Diego) for Commander, U.S. Pacific Fleet (COMPACFLT). In an RBAC solution, a resource manager does not have to constantly query personnel records to determine resource access. The resource manager establishes conditions based on a user's characteristics (command assignments, clearances, and/or pay grade) versus their name or unique identifier. The SEAC RBAC design surpasses the NIST RBAC standard requirements and can be used by any U.S. Government organization. Chapter 1 provides the reader with a general background on RBAC and other access.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号