The platform will undergo maintenance on Sep 14 at about 7:45 AM EST and will be unavailable for approximately 2 hours.
2010 2nd IEEE International Conference on Information Management and Engineering 2010
DOI: 10.1109/icime.2010.5477832
|View full text |Cite
|
Sign up to set email alerts
|

Research and implementation on access control of management-type SaaS

Abstract: In the paper, we analyze the features of access control of management-type SaaS. Based on the traditional RBAC, we put forward the access control model based on both tenant and role, in which the tenant is as the minimum unit of administrative domain. To be sure user identity with physical security, we put forward the hierarchical authentication and management of user in the management-type SaaS. In order to ensure the access control model of management-type SaaS in line with the reality, we abolish the inheri… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
2
0
1

Year Published

2012
2012
2015
2015

Publication Types

Select...
3
2

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(3 citation statements)
references
References 9 publications
0
2
0
1
Order By: Relevance
“…自主访问控制(DAC) [2] 、强制访问控制(MAC) [3] 、基于 角色的访问控制(RBAC) [4] 。但对于 SaaS 模式来说, 不管是安全性还是可管理性,已有的访问控制方法都 不能够很好地适用,所以需要根据 SaaS 模型的特点提 出新的访问控制模型。目前,国内外学者对此问题已 经做出了相关研究,Jing Xu 等人通过禁用 RBAC 模 型角色间的继承关系来防止角色间的权限继承,从而 防止权限扩散的危险,达到安全的访问控制 [5] 。Yuri …”
Section: 基于租户的访问控制模型 T-arbacunclassified
“…自主访问控制(DAC) [2] 、强制访问控制(MAC) [3] 、基于 角色的访问控制(RBAC) [4] 。但对于 SaaS 模式来说, 不管是安全性还是可管理性,已有的访问控制方法都 不能够很好地适用,所以需要根据 SaaS 模型的特点提 出新的访问控制模型。目前,国内外学者对此问题已 经做出了相关研究,Jing Xu 等人通过禁用 RBAC 模 型角色间的继承关系来防止角色间的权限继承,从而 防止权限扩散的危险,达到安全的访问控制 [5] 。Yuri …”
Section: 基于租户的访问控制模型 T-arbacunclassified
“…Xu et al [9] propose a new hierarchical access control model for the SaaS model. Their model adds higher levels to the access control policy hierarchy to be able to capture new roles such as service providers' administrators (super and regional) and tenants' administrators.…”
Section: Related Workmentioning
confidence: 99%
“…Literature [5] adopted a layered approach and proposed an access control method for SaaS platform on the basis of RBAC. Literature [6] also proposed an access control method for SaaS platform; this method disabled the role of inheritance and showed the user the accessing processes by UML diagram, but roles and tenants were in a multi-to-multi relationship and they might easily suffer from conflicts. A multi-tenant access control model was introduced in literature [7], but could not achieve role inheritance on the level of tenant.…”
Section: Introductionmentioning
confidence: 99%