计算机应用 ›› 2010, Vol. 30 ›› Issue (07): 1797-1801.

• 信息安全 • 上一篇    下一篇

基于RBAC的灵活代理委托模型

孙伟1,王淑礼2,邬长安2   

  1. 1. 信阳师范学院
    2.
  • 收稿日期:2010-01-06 修回日期:2010-02-17 发布日期:2010-07-01 出版日期:2010-07-01
  • 通讯作者: 孙伟
  • 基金资助:
    国家自然科学基金资助项目;信阳师范学院青年科研基金

Flexible Agent delegation model based on RBAC

  • Received:2010-01-06 Revised:2010-02-17 Online:2010-07-01 Published:2010-07-01

摘要: 在现有基于RBAC的委托模型中,委托人由于出差或休假无法自主执行委托,然而完全依靠管理员集中式的授权管理,缺乏灵活性,且存在权限滥用的危险。结合RBAC模型,提出一种基于代理的灵活角色委托模型。给出了代理委托策略,并通过构造和规约两方法对模型的合理性与完备性进行了论证。理论分析与实例验证结果表明,该模型通过引入代理人,代表执行并对委托过程进行监督管理,能够有效地体现委托过程的灵活性,并且遵循“最小特权”和“职责分离”两安全原则。

关键词: 基于角色的访问控制, 委托, 代理, 约束, 安全性, 灵活性

Abstract: The existing delegation models based on RoleBased Access Control (RBAC) lack flexibility, and the permissions abuse may occur in case that delegators are on business or on leave, although the system administrator could accomplish delegation authorization by oneself instead of delegators. This paper presented an Agentbased flexible role delegation model based on RBAC. The delegation strategy was given and the soundness and the completeness of the model were discussed and proved by the construction and the reduction methods. The results analyzed by theories and actual examples show that, the third party (or same Agent) takes charge of delegating the permissions on behalf of the delegator and supervises the delegation authorization. Flexibility is effectively reflected in the delegation, and the model follows the two security principles: "least privilege" and "the separation of duty".

Key words: Role-Based Access Control(RBAC), delegation, agent, constraints, security, flexibility