Web Authorization and Access Control System Based on Role

王宇,谷大武,苏丹
DOI: https://doi.org/10.3969/j.issn.1000-3428.2004.z1.107
2004-01-01
Abstract:This paper offers a system about authorization and access control. This system contains privilege management subsystem and access control subsystem. Privilege management subsystem makes all kinds of polices for the whole situation by diversified modules. In this subsystem, attribute authority (AA) or souse of authority (SOA) signed all kinds of policy attribute certificate, and administrators allocate privilege to users by attribute registration authority (ARA) and apply for users attribute certificate from AA. In the access control subsystem, the access control enforcement function (AEF) achieves users access requests and users identities and sends the information to the access control decision function (ADF). ADF calculates the users granted privilege and makes the permit or refuse decision based on the policy and the users attribute certificate made by the privilege management subsystem. Consequently, the system realizes the authorization and access control and ensures the security of the shared data in the back Web servers.
What problem does this paper attempt to address?