Access Control Service for Enterprise Applications

Zhu Donglai,Han Weili
DOI: https://doi.org/10.3321/j.issn:1002-8331.2006.05.061
2006-01-01
Abstract:Usually there are many application systems in an enterprise.These applications mostly need an access control module to control access to sensitive information in the enterprise.But it is complicated and fallible for the security administrator(or system security officer) to manage all security policies in different applications.This paper introduces an access control service for multi enterprise applications which is based on J2EE(Java 2 platform,Enterprise Edition).The paper discusses three methods to invoke reference monitor of the access control service,embedded invoking,asynchronized embedded invoking using JMS and asynchronized distributed invoking using JMS.These methods can meet the different requirements of enterprise applications.finally,the paper discusses some guidelines and technologies which optimize the efficiency of reference monitor.
What problem does this paper attempt to address?