Object-based Multi-Subject Access Control Model
LI Chang-cheng,LIU Cheng-ying,HONG Ming-song,CAI Wei
DOI: https://doi.org/10.3969/j.issn.1006-5911.2005.03.008
2005-01-01
Computer Integrated Manufacturing Systems
Abstract:Based on study of the role-based access control (RBAC) model and the team-based access control (TMAC) model, combined with the characteristics of the technological process information management, an object-based multi-subject access control model was proposed. In this model, object's access control strategy could be inherited through the object's inheritance hierarchies and the type of access subject was expanded to more types. The model implemented a fine-grained security administration at the level of individual users and individual objects. And the access permissions were assigned effectively and were easy to be expressed. As an active security model, it considered the context of objects and users when activating the permissions. Finally, an application example was introduced to prove the feasibility and advantages of this model.