Capability-based delegation model in RBAC

Capability-based delegation model in RBAC
复制标题

RBAC 中基于能力的委派模型

DOI:
--
复制
发表时间:
2010
期刊:
ACM Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
A. Matsushita
A. Matsushita
中科院分区:
--
文献类型:
--
作者:
Koji Hasebe;Mitsuhiro Mabuchi;A. Matsushita

文献摘要

被引文献

相似文献

为了在用户协作以完成其共同任务的环境中进行灵活和动态的资源管理,已经提出了使用基于角色的访问控制(RBAC)模型来对授权进行建模的各种尝试。然而,为了在大型网络系统中实现更高级别的协作,支持跨域委托并降低管理成本是值得的。为此,我们提出了一个基于能力角色的访问控制(CRBAC)模型,通过集成基于能力的访问控制机制到RBAC96模型。该方案的核心是在每个域中将能力映射到权限和角色,从而通过能力转移实现权限和角色的委托。通过采用这种基于能力的访问控制方法,我们的模型具有灵活性和降低管理成本的优点。我们还证明了我们的模型的有效性,通过使用各种类型的委托在临床信息系统的例子。
For flexible and dynamic resource management in environments where users collaborate to fulfill their common tasks, various attempts at modeling delegation of authority have been proposed using the role-based access control (RBAC) model. However, to achieve a higher level of collaboration in large-scale networked systems, it is worthwhile supporting cross-domain delegation with low administration cost. For that purpose, we propose a capability-role-based access control (CRBAC) model, by integrating a capability-based access control mechanism into the RBAC96 model. Central to this scheme is the mapping of capabilities to permissions as well as to roles in each domain, thereby realizing the delegation of permissions and roles by capability transfer. By taking this approach of capability-based access control, our model has the advantages of flexibility and reduced administration costs. We also demonstrate the effectiveness of our model by using examples of various types of delegation in clinical information systems.