Role delegation in role-based access control

Role delegation in role-based access control
复制标题

基于角色的访问控制中的角色委派

DOI:
10.1145/344287.344300
复制
发表时间:
2000
期刊:
--
影响因子:
--
通讯作者:
Suh
Suh
中科院分区:
--
文献类型:
--
作者:
S. Na;Suh

文献摘要

参考文献

被引文献

相似文献

在分布式计算环境中,应用程序或用户必须共享资源并相互通信,以更高效地执行他们的工作。为了提高性能,确保资源和信息的完整性不被未经授权的用户意外使用是很重要的。因此,对分布式共享资源的认证和访问控制有着强烈的需求。目前已经提出了三种访问控制:自主访问控制(DAC)、强制访问控制(MAC)和基于角色的访问控制(RBAC)。在RBAC中,存在高级角色可以执行初级角色权限的角色层次结构。然而,初级角色有时需要执行高级角色的许可,这基本上是初级角色不允许的。在本文中,我们将提出一种角色委托方法,由角色委托服务器和角色委托协议组成。我们根据触发对象将委托分为两类:主动委托和被动委托。因此,初级角色可以获得高级角色的权限。
In distributed-computing environments, applications or users have to share resources and communicate with each other to perform their jobs more efficiently. For better performance, it is important to keep resources and the information integrity from the unexpected use by unauthorized user. Therefore, there is a strong demand for the authentication and the access control of distributed-shared resources. Nowadays, three kinds of access control, discretionary access control (DAC) mandatory access control (MAC) and role-based access control (RBAC) have been proposed. In RBAC, there are role hierarchies in which a senior role can perform the permission of a junior role. However, it is sometimes necessary for a junior role to perform a senior role’s permission, which is not allowed basically by a junior role. In this paper, we will propose a role delegation method, consisting of a role delegation server, and a role delegation protocols. We divide the delegation into two by the triggered object: active delegation and passive delegation. Consequently, a junior role can gain a senior role’s permissions.
分布式对象系统的基于角色的可串行性
DOI: --
发表时间: 2006
期刊:
影响因子: --
作者:
Tanaka;Y.;Enokido;Y.;Takizawa;M.
通讯作者: M.