透過您的圖書館登入
IP:18.191.216.163
  • 學位論文

以角色為基之強化型存取控管架構應用於協同合作環境

Augmented RBAC Structure for the Collaborative Environment

指導教授 : 吳銜容
若您是本文的作者,可授權文章由華藝線上圖書館中協助推廣。

摘要


隨著全球化市場的來臨與運籌管理的推動,企業面臨的競爭也越來越激烈。然而,現今企業獨力經營方式已逐漸無法在劇烈競爭環境下生存,因此企業為了有效提升競爭力,則有賴於企業之間的協同合作,其帶來之優勢可以減少企業成本支出及提升企業作業效益。在多位使用者協同合作的環境中,安全的維護也倍增困難,尤其是使用者存取權限配置與控管。管理者若要給予使用者差異化的存取權限,會造成系統管理的負荷增加;若不當的存取權限配置,則會使系統安全性降低。針對上述問題之解決,本研究提出一個ARBAC model(Augmented Role-Based Access Control)架構,此架構是以RBAC 概念為基礎加以延伸,並強化Role 的管理。由於以往RBAC 概念是應用於作業系統的領域,而未考慮協同作用之需求,因此在第一階段的架構建置,本研究以協同群組概念(意指專案計劃型之協同合作群組)為主重新定義RBAC,以適用於協同合作方式;在第二階段的架構建置,分別以時間概念、Role 行為與環境因素之管理類別,強化Role的管理,進而提升使用者存取權限控管能力。以時間概念之管理類別,是利用時間的定義來配置Role 的應用;以Role 行為之管理類別,是管理Role 配置與存取對象;以環境因素之管理類別,則是建立環境因素與Role 的關聯,以利於Role 配置的管理。本研究透過實際企業個案探討,以及ARBAC model 架構的建置,其目的是提升企業之間協同合作方式的安全性,並達到適性化與彈性化的使用者存取權限控管。

並列摘要


Nowadays, due to the trend of the global market and growth of CALS (Continuous Acquisition and Life-cycle Support), the business environment has become more and more competitive. Hence,collaboration is important and required to incrase the efficiency of product development for the enterprise. However, security issue of collaboration is ignored, especially that of access control. It results in unsecure collaboration for user, data and environment of the enterprise without effective access control. In order to slove the problem regarding security of access control in the collaborative environment, this research proposes an ARBAC (Augmented Role-Based Access Control) model. It extends the RBAC concept for the collaboration and enhances role management. The proposed ARBAC model includes three classes for role management: time-based class, behavior-based class and environment-based class. Time-based class is used to assign role by various time definition; behavior-based class is used to deal with role application; environment-based class is used to create the relationship between environment and role to improve the role assignment. This ARBAC model provides flexible access control and meets diversied user requirement. The aim of this research is to improve security in the collaborative environment and achieve adaptive access control with flexible role assignment and management.

並列關鍵字

collaboration access control ARBAC mdel

參考文獻


6. 黃敬仁、張瑞芬、姚銀河,「WfMC 為基之模組化網路協同設計系統分析與建置」,工業工程學刊,第四卷第二十期,422-432 頁,2003 年。
1. G. J. Ahn, “Specification and classification of role-based authorization policies,” in Proceedings of 12th IEEE International Workshops on Enabling Technology: Infrastructure for Collaborative Enterprises, 2003.
2. M. A. Al-Kahtani and R. Sandhu, “Rule-based RBAC with negative authorization,” in Proceedings of 20th Annual Computer Security Applications Conference, 2004.
3. C. J. Anumba, O. O. Ugwu, L. Newnham, and A. horpe, “Collaborative design of structures using intelligent agent,” Automation in Construction, 11, 2002, pp. 89-123.
4. E. Barka and R. Sandhu, “Framework for role-based delegation models,” in Proceedings of 16th Annual Computer Security Applications Conference, 2000, pp. 168-176.

延伸閱讀