节点文献

XML数据库的扩展RBAC模型构建

Building of Extended RBAC Model for XML Database

【作者】 王宁娟

【导师】 赵合计;

【作者基本信息】 山东大学 , 计算机软件与理论, 2011, 硕士

【摘要】 随着Internet突飞猛进地发展,基于互联网的应用越来越深入,而XML无论是作为标记语言还是被作为存储结构的数据库都随着Internet上的各种应用增多而被越来越广泛的应用。为了解决XML作为信息载体的广泛应用带来的安全问题的安全服务模型——安全访问控制模型,已成为现在人们研究的焦点。本课题将以传统的基于XML文档RBAC(基于角色的访问控制)模型作为文章研究的出发点,从而提出了基于XML文档数据库的扩展RBAC模型。该模型使用了Schema语言来定义了XML数据库文档结构,针对XML文档的特性,在分析基于XML的RBAC模型存在角色授权过于庞大和约束机制不完善的问题基础上,对其进行有效的改造和扩展,提出了一种新的基于XML文档的扩展RBAC模型。文章分析了传统的RBAC模型存在的问题,并在此基础上针对这些问题提出了解决方案——基于XML文档的扩展RBAC模型,并对新的扩展RBAC模型进行完整的定义和详细的说明。论文中还结合了实例模型集中从基于XML文档的扩展RBAC模型的系统实现及其系统实现所需的主要技术支持进行考虑,针对基于XML文档的扩展RBAC模型的设计,结合一个简化的企业内部人员管理信息系统为访问控制模型的应用环境,进行更为直观和深入的描述并具体展示了在基于XML文档的数据库中,实现扩展的RBAC系统所使用的关键性技术。本论文首先对访问控制模型中的客体按照其属性进行抽象归类,再将权限配置给一类客体,模型中的主体对客体的访问权限,是由主体对应的角色和访问域共同来确定,这样极大地减少了角色和权限的定义数量。其次文章采用的是职责关系隔离(separation of duties)规则来解决系统中角色间存在的利益冲突,以避免用户权限过大或者用户越位越权等现象出现,而影响系统的安全性能。文章还将使用schematron(基于规则的XML模式语言)来对约束规则进行形式化描述。基于XML文档的扩展RBAC模型能够符合XML文档细粒度的访问控制需求,该模型结构简洁灵活且比较容易实现。

【Abstract】 With the rapid development of Internet, more and more in-depth Internet-based applications, and XML is either as a markup language, or it is used as the stored structure of the databases on a variety of applications as the Internet has been growing more and more widely used. XML as an information carrier in order to solve the security problems caused by widely used security services model - secure access control model, has become the focus of research is now.This paper takes the traditional role-based access control (RBAC) model as the starting point of the study,and puts forward the extended RBAC model that based on the XML document database.This model uses the Schema language to define the document structure of the XML database,according to the characteristics of the XML document,on the problem that the role model authorized redundantly and the constraint mechanism performed imperfectly of the RBAC model that based on XML,we put forward a new extended RBAC model that based on XML documents which is effective and expansive.This paper analyzes existing problems of the traditional RBAC model, and on this basis puts forward the solution of these problems-the extended RBAC model that based on the XML documents, and completely defines and details to the new extended RBAC model. The paper combines instance model and focus from the implementation of system and needed technical supports for the extended RBAC model that based on the XML documents to consider, and directs at the design of the extended RBAC model that based on the XML documents, combines the technical support for the main consideration for the extension of RBAC-based XML document model design, and combined with a simplified internal staff management information system as the application environment to access control model to describe which more intuitive and in-depth,and definite shows that achieved the key technologies for the extended RBAC system on the database that based on the XML documents.Firstly, in this paper,we classify the object of the access control model abstractly according to their attributes,then assign the permissions to a class of objects.The access permission of the subject to the object in the model is decided by the corresponding roles and access domain of the subject,this way can greatly reduce the number of the roles and permissions definitions. Secondly,this paper adopts the rules of separation of duties to solve the roles’ interest conflict in the system,in order to avoid the phenomenon that the users have excessive permissions or the users beyond their authorities which affects the security performance of the system.In addition,this paper also uses the schematron(the XML schema language based on rules) to describe the constraint rules formally.The extended RBAC model that based on XML document can satisfy the fine-grained access control requirements of the XML document.This model’s structure is simple and flexible,and it’s easy to be realized.

【关键词】 XMLRBAC公共访问域特定访问域约束规则
【Key words】 XMLRBACPADSADConstrained Rules
  • 【网络出版投稿人】 山东大学
  • 【网络出版年期】2012年 04期
节点文献中: 

本文链接的文献网络图示:

本文的引文网络