计算机与现代化 ›› 2010, Vol. 1 ›› Issue (5): 164-166.doi: 10.3969/j.issn.1006-2475.2010.05.046

• 信息安全 • 上一篇    下一篇

RBAC在B/S模式信息管理系统中的研究与实现

张先勇,李 勇,张 浩   

  1. 五邑大学信息学院,广东 江门 529020
  • 收稿日期:2009-10-14 修回日期:1900-01-01 出版日期:2010-05-10 发布日期:2010-05-10

Research and Realization of Role-based Access Control in B/S Model of Information Management System

ZHANG Xian-yong, LI Yong, ZHANG Hao   

  1. College of Information, Wuyi University, Jiangmen 529020, China
  • Received:2009-10-14 Revised:1900-01-01 Online:2010-05-10 Published:2010-05-10

摘要: 基于角色的访问控制(RBAC)具有减少授权管理复杂性、降低管理开销、增强系统安全性等优良特性。本文分析了RBAC模型的基本原理、结构,描述了RBAC在B/S模式信息管理系统中的应用模型,并将这种新的应用模型应用到某公司的业务信息管理系统开发中,实现了用户与角色相关联、角色与权限相关联,不同用户拥有不同的操作权限,增加了系统使用的安全性以及系统管理的工作效率。

关键词: 基于角色的访问控制(RBAC), B/S, 信息管理系统(MIS), 权限管理

Abstract: RBAC has many excellent characteristics, for example, it can reduce the complexity of authorization management, lower management costs, enhance system security and so on. This paper analyzes the basic principle and architecture of RBAC model. RBAC is described in the B/S model of information management system, and the new model is applied to a company's business information management system development. The association between users and roles, and roles and permissions is realized. So different users have different operating authority in this business information management system. In addition, the system’s security and management efficiency are improved.

Key words: role-based access control, B/S, management information system, privilege control

中图分类号: