分析了Web应用系统在访问控制方面的需求和现有RBAC模型应用于Web应用系统中的不足,提出了一个基于NIST发表的RBAC建议标准的访问控制模型WERBAC。该模型对RBAC建议标准中角色和权限的概念进行了定义和扩充,在此基础上介绍了对页面的多维度和细粒度控制,并给出了一个该模型的应用实例。
The access control requirements of web application system and the shortcomings in web application system with RBAC model are analysed. Then an extended model named WERBAC (Web-extended RBAC) is proposed, based on the NIST's RBAC propositional standards. WERBAC extends and defines roles and privileges of the NIST RBAC, and introduces the multiple dimensions and fine- grained controls for the pages. Finally, an instance is given using the WERBAC.