基于角色的存取控制(RBAC ) 的主要优点能支持著名安全原则和角色的继承。要不是在那里为 RBAC 仍然是特定的定义和必要形式化的缺乏,它对在实际工作的 realizeR 用绳子拖的平底渡船难。我们这里的贡献是形式化 RBAC 的主要关系并且采取第一项措施建议行动闭合和一个角色,我们为一个角色的最少的特权基于得到了说明和算法的数据闭合的概念。我们建议角色的继承应该由行动的继承和数据的继承组成,然后我们在角色之中得到特权的继承,它能被存在也支持利用工具。
The main advantages of role-based access control (RBAC) are able to support the well-known security principles and roles'inheritance. But for there remains a lack of specific definition and the necessary formalization for RBAC, it is hard to realize RBAC in practical work. Our contribution here is to formalize the main relations of RBAC and take first step to propose concepts of action closure and deta closure of a role, based on which we got the specification and algorithm for the least privileges of a role. We propose that roles' inheritance should consist of inheritance of actions and inheritance of data, and then we got the inheritance of privileges among roles, which can also be supported by existing exploit tools.