论文部分内容阅读
As an important part of access control,authorization is performed mostly by system administrator in most PDM systems.RBAC is widely used in these PDM systems,which has been regard as a policy independent access control model.In RBAC,delegation can easy authorization operation of system administrator in PDM system,which has large number of user and access object.However,in existing PDM system,delegation security entirely depends on delegators and security administrators,for delegation constraint in these models is only a prerequisite condition,thus makes PDM system less secure.Based on existing delegation models in PDM systems,this paper proposes an Attribute-Based-Delegation-Model (ABDM) with an extended delegation constraint consists of both delegation attribute expression (DAE) and delegation prerequisite condition (CR).In ABDM,A delegatee must satisfy delegation constraint (especially DAE) when assigned to a delegation role.With delegation constraint,a delegator can restrict the delegatee candidates more strictly.ABDM relieves delegators and system administrators of security management work in PDM system.This paper also introduce an example to show how ABDM works in privilege management in PDM system.