Abstract

In order to overcome the problems of the classic RBAC model, such as user identity cannot be verified, role assignment conflicts, permission leakage, complicated roles and permissions configuration, etc., this paper proposes a dual-role hierarchical RBAC extended security model based on department attributes. Firstly, based on the identity authentication mechanism, the legality of the user identity used by the system and its department attributes are authenticated, and the legal identity users are associated with their departments. Then, the roles were divided into responsibility roles and system roles in the classic RBAC model, which are defined by the system administrator is responsible for configuring system roles according to the permission control requirements of resources and operations in the system. The person in charge of the department to which the user belongs configures the role for the user according to the actual work responsibilities of each user, and the person in charge of the department is responsible for the relationship between the role and the system. Finally, this dual-role hierarchical RBAC extended security model based on department attributes is applied to the authority management scheme of a power grid business system. The security analysis and practical results show that this dual-role hierarchical RBAC extended security model based on department attributes is a system rights management solution with strong security and practicability.

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.