计算机科学 ›› 2012, Vol. 39 ›› Issue (11): 13-18.

• 综述 • 上一篇    下一篇

RBAC模型研究历程中的系列问题分析

刘强 王磊 何琳   

  1. (广东工业大学c工MS重点实验室 广州 510006)
  • 出版日期:2018-11-16 发布日期:2018-11-16

Research on a Series of Problems in RBAC Model

  • Online:2018-11-16 Published:2018-11-16

摘要: 长期以来,R13AC模型的研究工作主要集中在信息科学领域,其深厚的管理学背景与逻辑学背景并没有获得 关注。在综述RI3AC模型研究历程的基础上,揭示了RI3AC模型存在的一系列逻辑问题与管理问题:授权状态的“伪 三值逻辑”问题、管理权威的来源问题、管理员的权责同步问题、权限泄漏的含义问题、授权决策支持的模式问题。其 后,从语用/语法/语义3个层面进行分析并明确了R13AC模型的二值逻辑学基础;详细阐述了系列管理问题的逻辑 关系,分别分析了各个管理问题的背景和内涵,明确了管理权威的来源和权限泄漏的具体含义,提出了“有效区分分权 与授权、推行权限使用审计”的权责同步思路,及“以问题求解替代安全策略与约束语义显示化”的授权决策支持模式。 本研究旨在明确RI3AC模型中的一些核心概念与理论基础,揭示并解决一些关键问题,为提升RI3AC模型的安全性 与适用性、降低RI3AC;模型的复杂性提供理论层面上的支持。

关键词: 基于角色的访问控制,授权,安全,授权决策支持

Abstract: RI3AC is characterized by distributed management and self-management as the basic model in RBAC field. Today, many research themes on RI3AC arc almost proceeded in the field of information science, and its management and logistics background are ignored. This paper uncovered a series of management problems and logic problems existed during the research process on RI3AC, including false ternary logic basis of authorized state, un-synchronization between right and responsibility of administrators, ill-defined meaning of right leakage, unclear resource of authority, and failure in decision-making during authorizing process etc. Then it analyzed the false ternary logic problem from a logic view with a three layer framework in detail, described the background, content and deriving relationships of other manage- ment problems from a management view, explained the meaning of right leakage and origin resource of authority, put forward the mechanism on the synchronization of right and responsibility and the corresponding audit system, and de- signed the decision support mode for the administrators when authorizing. These research can provide theoretical sup- port for the development and update of RI3AC model.

Key words: RI3AC, Authority assigning, Safety, Authority assigning decision support

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!