標題: 基於角色與屬性的存取控制系統之泛型化策略規範模式
Generic Policy Specification Paradigm for Attribute-Enriched Role Based Access control
作者: 阮哿壽
Nguyen, Kha-Tho
邵家健
John, Kar-kin Zao
資訊科學與工程研究所
關鍵字: 基於角色的存取控制;基於角色與屬性的存取控制系統;泛型化策略規範;Role Based Access Control;Attribute-Enriched Role-Based Access Control;Generic Policy Specification
公開日期: 2012
摘要: 在本論文中,介紹了一個基於角色與屬性的存取控制之泛型化策略規範模式。這個規範模式中,在傳統角色模組裡加進了參數和次型別的多型性,並添加物件角色, 以及一個彈性的指定存取控制策略的主體和對象角色之間關聯機制。配合型別檢查的功能,這個規範可以容易的在撰寫策略時檢查錯誤。我們還定義了一個支持泛型 編程的宣告式語言。此規範允許我們使用有彈性、有效率、可驗證、可重複利用的方式來設計安全策略
This work introduces a generic paradigm for specifying attribute enriched RBAC security policies. Our paradigm has enriched the conventional role model with parameterized and subtype polymorphism and added object roles entity as well as flexible associations between subject and object roles as the mechanism to specify access control policies. With the support of type checking this paradigm can easily verify some errors while writing policy. We have also defined a declarative language with the support of generic programming. Paradigm allows designing security policies in a more flexible, efficient, verifiable, reusable way
URI: http://140.113.39.130/cdrfb3/record/nctu/#GT079955630
http://hdl.handle.net/11536/50536
Appears in Collections:Thesis