随着应用服务提供商(ASP)模式的发展,为解决集成了越来越多应用服务的ASP平台与用户之间复杂的管理需求,提出了一种ASP模式下用户授权代理机制的角色访问控制(UD_RBAC)模型.文中对UD_RBAC模型形式化描述,细致地分析了其构成要素、用户授权代理管理模式和实施策略.采用LDAP目录访问协议统一存储用户身份和权限信息,通过代理策略保护应用服务资源,实现对用户的访问进行分级授权和控制.
With the development of the application service provider(ASP)pattern,to solve the complicated management requirements between users and services in ASP service platform,this paper presents a role-based access control based on user delegation mechanism in ASP pattern(UD-RBAC).The paper uses a formalization to describe the UD_RBAC model,analyses it's user delegation management and brings it's strategy into effect,All user's identification and authorization information were stored in a light-weight directory access protocol(LDAP),policy agents were set up to protect the application service resources,and implemented Layered Authorization and control for user's access.