{"title":"Task-role based access control model in logistics management system","authors":"Yingying Yu, Yan Chen, Yuqin Wen","doi":"10.1109/SOLI.2013.6611396","DOIUrl":null,"url":null,"abstract":"Access control model that decides whether a principal is allowed access to a resource plays a protective role in information system. This paper argues the merits and shorts of four typical models at first, and then presents an integrated access control model-TRBAC which introduces the concept of task into RBAC model. We set up the specific structure of TRBAC and give detail definitions of the constraints in roles and tasks. Based on the TRBAC model, further study is made according to the actual requirements of access control in LMS (Logistics Management System). We establish the architecture of access control model in LMS and introduce several main functional modules. After that this paper emphatically describes how to design and implement the three major controllers including role controller, task controller and permission controller in LMS based on PaaS(Platform as a Service), with the system interfaces visually. In practical, with the combination of task and role, the TRBAC model associates the user with permission indirectly, makes the static and dynamic double control come true and assigns the permission according to the actual needs. The TRBAC model has achieved good results in the implementation of the practical application. It turns out that the model is reasonable and stable which has a practical significance and necessity.","PeriodicalId":147180,"journal":{"name":"Proceedings of 2013 IEEE International Conference on Service Operations and Logistics, and Informatics","volume":"138 38","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-07-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of 2013 IEEE International Conference on Service Operations and Logistics, and Informatics","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SOLI.2013.6611396","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Access control model that decides whether a principal is allowed access to a resource plays a protective role in information system. This paper argues the merits and shorts of four typical models at first, and then presents an integrated access control model-TRBAC which introduces the concept of task into RBAC model. We set up the specific structure of TRBAC and give detail definitions of the constraints in roles and tasks. Based on the TRBAC model, further study is made according to the actual requirements of access control in LMS (Logistics Management System). We establish the architecture of access control model in LMS and introduce several main functional modules. After that this paper emphatically describes how to design and implement the three major controllers including role controller, task controller and permission controller in LMS based on PaaS(Platform as a Service), with the system interfaces visually. In practical, with the combination of task and role, the TRBAC model associates the user with permission indirectly, makes the static and dynamic double control come true and assigns the permission according to the actual needs. The TRBAC model has achieved good results in the implementation of the practical application. It turns out that the model is reasonable and stable which has a practical significance and necessity.
访问控制模型在信息系统中起着保护作用,它决定一个主体是否被允许访问某一资源。本文首先分析了四种典型模型的优缺点,然后在RBAC模型中引入任务的概念,提出了一种集成的访问控制模型trbac。我们建立了TRBAC的具体结构,并给出了角色和任务约束的详细定义。在TRBAC模型的基础上,根据LMS (Logistics Management System)中访问控制的实际需求进行了进一步的研究。建立了LMS中访问控制模型的体系结构,并介绍了几个主要功能模块。然后着重介绍了基于PaaS(Platform as a Service)的LMS中角色控制器、任务控制器和权限控制器这三大控制器的设计与实现,以及系统界面的可视化。在实际应用中,TRBAC模型通过任务与角色的结合,将用户与权限间接关联起来,实现静态和动态双重控制,并根据实际需要分配权限。该TRBAC模型在实际应用中取得了良好的效果。结果表明,该模型是合理的、稳定的,具有一定的现实意义和必要性。