首页 | 本学科首页   官方微博 | 高级检索  
     检索      

CMS中RBAC模型的改造和应用
引用本文:曹勇刚,金茂忠,刘超.CMS中RBAC模型的改造和应用[J].北京航空航天大学学报,2005,31(10):1153-1158.
作者姓名:曹勇刚  金茂忠  刘超
作者单位:北京航空航天大学 计算机学院, 北京 100083
基金项目:国家高技术研究发展计划(863计划)
摘    要:针对内容管理系统(CMS)中内容、权限和用户数量规模大的特点,采用形式化方法定义了改造后的基于角色的权限模型--RBAC0.5.对照RBAC96定义的4个模型,RBAC0.5是一个介于RBAC0和RBAC1之间的新模型.它覆盖了RBAC0,将RBAC1中的角色层次关系改造为通过用户组关联的映射关系,从而获取以关系型数据库为后台的集合操作能力.并且,为了有效组织CMS中的内容,形式化定义了内容分区和层次分类,在此基础上定义了层次化的权限集合,从而支持多层粒度上的访问控制.基于上述模型, 给出CMS中基于短路操作、垃圾收集以及缓存技术的实现访问控制的优化算法.

关 键 词:内容管理系统  访问控制  形式化方法  算法  模型
文章编号:1001-5965(2005)10-1153-06
收稿时间:2004-11-19
修稿时间:2004年11月19日

Modified RBAC model and its application on content management system
Cao Yonggang,Jin Maozhong,Liu Chao.Modified RBAC model and its application on content management system[J].Journal of Beijing University of Aeronautics and Astronautics,2005,31(10):1153-1158.
Authors:Cao Yonggang  Jin Maozhong  Liu Chao
Institution:School of Computer Science and Technology, Beijing University of Aeronautics and Astronautics, Beijing 100083, China
Abstract:Focusing on the large scale characteristic of content, users and permissions in content management system (CMS), a modified role based access control(RBAC) model, RBAC0.5, is formally defined. In contrast with the four models defined by RBAC96, the RBAC0.5 is formed as a new model between the basic model (RBAC0) and the enhanced model (RBAC1). It covers RBAC0 and alters the hierarchical relations among roles in RBAC1 to flat mapping by introducing the middle layer--user group. By using RBAC0.5, set operation can be performed with the relational database back-end. In addition, the partition and hierarchy category are formally defined for the arrangement of content in CMS by their media type and their semantic. Based on those definitions, the multi-layer permission sets are defined on partitions and categories for the multi-grained access control. According to such models, the implementation of the access control in the CMS uses short circulating operation, garbage collection and caching technology for performance optimization. Pseudo codes of the algorithms are also given.
Keywords:content management system  access control  formal logic  algorithms  model
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《北京航空航天大学学报》浏览原始摘要信息
点击此处可从《北京航空航天大学学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号