An improved mechanism of authorization control based on Web environment

LI Bo,HUANG Dong-jun
DOI: https://doi.org/10.3969/j.issn.1006-8937-B.2006.04.001
2006-01-01
Abstract:The paper analyzes and compares several primary ways to distribute privileges during the current design process of access system such as Discretionary Access Control(DAC), Mandatory Access Control (MAC) and Role-Based Access Control (RBAC), points out their respective characteristics and limitations of their applicability. By taking the new characteristics of modern enterprise management into consideration and combining with the existing access control model, the authors discuss the access control technology of the multi-users information system, present and realize the security control model based on role level, department level and user level in the application. Practical application makes clear that it enhances the security and maintainability of information system.
What problem does this paper attempt to address?