计算机科学 ›› 2010, Vol. 37 ›› Issue (12): 47-52.

• 计算机网络与信息安全 • 上一篇    下一篇

基于多亲树的RBAC角色可视化管理

封孝生,黎湘运,孙扬,张维明   

  1. (国防科技大学C4ISR技术国防科技重点实验室 长沙410073)
  • 出版日期:2018-12-01 发布日期:2018-12-01
  • 基金资助:
    本文受国家自然科学基金(60903225)和(70971134)资助

Facilitating Role Management in RBAC:Using Multi-parents Tree

FEND Xiao-sheng,LI Ximg-yun,SUN Yang,ZHANG Wei-ming   

  • Online:2018-12-01 Published:2018-12-01

摘要: 基于角色的访问控制(RRAC)被广泛地应用于各类复杂信息系统中,通过对用户指派角色进行授权以访问系统中的特定数据或资源。一些问题已在应用过程中逐渐暴露:如何较好地展现角色层次关系、用户角色指派和角色指派中约束如何体现、冗余的角色授权如何检测与解除等。从可视化的角度采用层次信息可视化技术来辅助RRAC中的角色管理。首先阐述了所研究的问题,并定义了可视化过程中使用的多亲树结构;然后给出一个多亲树规范化过程,以建立一个符合可视化要求的标准角色层次;随后提出一种双层可视化范例来展示角色管理过程,其中下层用于展示角色层次和权限,上层用于配置用户节点;此外,针对所述问题给出若干交互方法,以可视地辅助解决角色管理中的约束和冗余问题。

关键词: 基于角色的访问控制,角色管理,多亲树,角色层次,启发式布局

Abstract: Role-Based Access Control(RBAC) has been widely applied to authorize certain users to access certain data or resources within complex information systems. Several problems are coming about during the application of RBAC models, which include well-representing the role hierarchy, following the constraints applied in user-role assignments and role-role relations, revoking redundant roles and assignments, etc. This paper addressed these problems from the perspective of information visualization to facilitate role management in RBAC, particularly leveraging the experience of trees) visualization. A detailed problem statement was made first,and the data structure of multi-parents tree was defined. Then a multi-parents tree normalization process was proposed to construct a refined role hierarchy for elegant representation. Subsectuently, a two-layered paradigm, the nether for displaying role hierarchy and permissions, and the upper for placing uscrs,was presented for the visualization of role management in RBAC. Additionally,some specific interaction techniques were put forward to visually aid in solving the constraint and redundancy problems.

Key words: RBAC, Role management, Multi parents tree, Role hierarchy, Heuristic layout

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!