It analyzes the key factors of human resource modeling , the ways to select resource , the primary strategy base of allocating resources dynamically and the access control model of operating system and database system . because cmm ( capability maturity model ) and rup ( rational unified process ) are too complex to use properly in the small organization , a human resource management model of middle / small software developing organization is proposed . it is based on the cmm and rup model and combined with our working experience 本文分析了资源管理的要素、分配策略、确定了资源选择方法和权限管理方式,对人力资源进行建模管理,并参考cmm ( capabilitymaturitymodel )和rup ( rationalunifiedprocess )的资源管理,归并相关角色,结合作者的工作经验,提出了一个中小型企业软件开发人力资源模型,与资源管理模块配合使用。
Mac , nist - rbac access control model ; 2 . analyzes the access control needs of the applied electronic government system ; 3 . uses the language of uml to proceed the detailed design to the system of rbac ; 4 , uses the language of xml to describe access control information to the model of rbac and illustrates alternant techniques of xml realization in the distributed type of network environment ; 5 在访问控制设计部分,本文做了如下工作: 1 、对dac 、 mac 、 nist - rbac访问控制模型进行了分析比较; 2 、分析了电子政务应用系统的访问控制需求; 3 、用uml语言对rbac系统进行了较为详细的设计; 4 、用xml语言对rbac模型的访问控制信息进行了描述,并阐述了分布式网络环境下xml交互的实现技术。
Based on the analysis of current access control model , in chapter 3 the realization of mandatory access control in role - based protection system is discussed . at first , the definition of role and the application in security are discussed . then the concept of mac is introduced and a scheme of role - based protection is developed , which realizes mac by viewing each of the role contexts as a independent security - level and imposing non - cyclic information flow requirement 分析了目前已有的访问控制模型,提出了一个扩展rbac的安全约束实现强制访问控制的方法,其特点是利用信息流分析原理,把每个角色上下文看成一个安全标示,并确保信息流(由角色执行或用户? ?角色授权)是非循环的,通过给出的相关约束实现了B L P模型的有关规则。
Introducing the idea of fuzzy logic , this paper advances trust - authorization - based fuzzy access control model and exerts fuzzy synthetic judgment method to calculate subjects ' trust worthiness , establishes fuzzy control rules , automatically authorizes subjects ' relevant privilege by fuzzy adjudging , which can satisfy requirements of open information system access control 文中引入模糊逻辑的思想,提出了基于信任授权的模糊访问控制模型,运用模糊综合评判法计算出主体在开放式信息系统中的信任度,并建立模糊控制规则,通过模糊判决自动授予主体相应的权限,使其能够更好的满足开放式信息系统中访问控制的要求。