dRBAC模型是适应于动态结盟环境的分布式信任管理和访问控制机制,具有第三方委托、值属性和证书预定等三个特征.但dRBAC模型存在一些不足,体现在以下几个方面:委托的深度没有控制;委托链的循环搜索;角色的隐式提升;职责分离原则的违背等.本文针对dRBAC模型存在的问题进行了详细的讨论,提出了合理的解决方案,提高了dRBAC模型的安全性和实用性.
The dRBAC model is a scalable, decentralized trust-management and access-control mechanism for systems that span multiple administrative domains. The dRBAC model supports three feathers., third-party delegations, valued attributes, credential subscription. However, there are some limitations of the dRBAC model, which represent the following issues: no control on the depth of delegation, circular search for delegation chain, covert promotion of role, violating separation of duty. In this paper, these issues are discussed in detail, and reasonable resolutions of these issues are proposed in order to improve the security and practicability of the dRBAC model.