• 论文 •    

基于I-RBAC的CIMS集成访问控制

张东站,薛劲松,宋瀚涛   

  1. 1.北京理工大学计算机科学工程系,北京100081;2.中科院沈阳自动化研究所,辽宁沈阳110015
  • 出版日期:2004-01-15 发布日期:2004-01-25

CIMS Integrated Access Control Based on I-RBAC

ZHANG Dong-zhan, XUE Jin-song, SONG Han-tao   

  1. 1.Dep. of Computer Sci., Beijing Inst. of Tech., Beijing100081, China;2.Shenyang Inst. of Automation, Chinese Academy of Sci., Shenyang110015, China
  • Online:2004-01-15 Published:2004-01-25

摘要: CIMS面临复杂的数据资源的安全管理难题,传统的访问控制一般分散在网络操作系统、数据库管理系统、应用系统中,没有一个统一的安全控制策略。为此,在目前RBAC模型的基础上,提出了集成角色访问控制模型,并从静态和动态两方面研究了模型的内容和规则,给出了模型实现的体系结构,分析了角色的安全性。该模型已应用于某烟草集团CIMS建设中,使访问控制更好地适应了企业特定的安全策略。

关键词: 计算机集成制造系统, 角色, 访问控制, 集成继承, 会话分流

Abstract: One problem in CIMS is the complex security administration of data resource. The traditional access control is dispersed among the network OS, DBMS and application systems without uniform access control strategy. The Integrated Role Based Access Control (I-RBAC) Model for CIMS is presented based on the current RBAC model. The content and the rule of the model are studied through static and dynamic way. The structure of model is provided and the security of the role is analyzed. The model is applied to the CIMS of one tobacco group and makes the access control be seasoned with the special secure strategy of enterprise.

Key words: CIMS, role, access control, integrated inheritance, session diffluence

中图分类号: