针对UCON未涉及特权委托的基本特征和权限管理的缺陷,提出了基于属性RBAC的带委托性质的使用控制模型(EUCON).将角色、委托和扩展属性等要素引入到EUCON,构建了基于属性一角色的访问控制方法,提高了模型的可变性和动态性,并使用区间时序逻辑对该委托模型的完备性进行逻辑验证,最后提供了网上行政审批的实例,为模型的应用奠定了一个很好的实例基础.
As UCON model does not involve the, basic characteristics of the delegation and the usage of permissions is not wcll-manage,mcnt, a new model base, d on attribute- RBAC with character of dele,gation usage control is proposed. Key elemcnts sueh as role, delegation and extendeed-attributc into usage control are, introduced. A new access control method that based on attribute-role, which makes the model more, variably and dynamically is prcsented. In addition, Interval Temporal Logic is used for logically demonstrating the completeness of EUCON model based on delegation. Finally, an application of administrative, examination and approval is articulated, offering a good example for application of EUCON.