周志烽, 王晶. Design and Implementation of the Security Management Module Based on RBAC[J]. 2010, 23(10): 84-88. DOI: 10.13992/j.cnki.tetas.2010.10.017.
Design and Implementation of the Security Management Module Based on RBAC
摘要
本文通过研究RBAC(Role Based Access Control)的经典模型
针对Web资源访问的特点和安全问题
给出了Web系统安全管理模块的设计原则
然后以Spring Security作为框架
给出了安全管理模块的无侵入式的实现方法。
Abstract
By researching the classic models of RBAC
the article introduces several discipline of designing the security management module of web systems
aiming for solving the security problems of the web system. The article also introduces a way of implementing the security management module by means of the structure of spring security.
A role-based access control model and reference implementation within a corporate intranet [J] . David F. Ferraiolo,John F. Barkley,D. Richard Kuhn. ACM Transactions on Information and System Security (TISSEC) . 1999 (1)