计算机与现代化 ›› 2012, Vol. 1 ›› Issue (200): 79-03.doi: 10. 3969/j. issn. 1006-2475.2012.04.021

• 应用与开发 • 上一篇    下一篇

基于XACML的用户角色自动指派

谢卫星   

  1. 南华大学计算机科学与技术学院,湖南 衡阳 421001
  • 收稿日期:2011-10-14 修回日期:1900-01-01 出版日期:2012-04-16 发布日期:2012-04-16

XACML-based Automatic User Role Assignment

XIE Wei-xing   

  1. School of Computer Science and Technology, University of South China, Hengyang 421001, China
  • Received:2011-10-14 Revised:1900-01-01 Online:2012-04-16 Published:2012-04-16

摘要: AURA(Automatic User Role Assignment)能够大幅降低RBAC的管理开销。基于属性规则的访问控制机制能提供细粒度的访问控制。本文详细介绍基于XACML的AURA扩展、AURA中的XACML的策略语言模型、基于XACML的AURA的应用实例、基于XACML的AURA中存在的问题以及基于XACML的参考实现。

关键词: XACML, AURA, 属性, 规则

Abstract: AURA(Automatic User Role Assignment) can reduce the cost of administration dramatically. An attribute-based and rule-based access control mechanism can provide a thin-grain access control. The article introduces the extension, the policy language model, the application instance, the problem and the reference implementation of the XACML-based AURA in detail.

Key words: XACM, AURA, attribute, rule