5. 访问控制策略与机制 访问控制策略 (Access Control Policy): 访问控制策略在系统安全策略级上表示授权。是对访问如何控制 , 如何作出访问决定的高层指南 访问控制机制( Access Control Mechanisms): 是访问控制策略的软硬件低层实现 访问控制机制与策略独立可允许安全机制的重用 安全策略之间没有更好的说法 , 只是一种可以比一种提供更多的保护 , 应根据应用环境灵活使用
6. 访问控制策略 自主访问控制( discretionary policies) :基于身份的访问控制 IBAC(Identity Based Access Control) 强制访问控制 (mandatory policies), 基于规则的访问控制 RBAC ( Rule Based Access Control ) 基于角色的访问控制 RBAC ( Role Based Access Control )
35. Kasai : RBAC 的开源实现 What is Kasai? Kasai is a 100% Java based authentication and authorization framework. It allows you to integrate into your application a granular, complete and manageable permission scheme. The goal of the framework is to provide a simple-to-use-yet-powerful security environment for multi-user applications.
36. 开源项目 Kasai http://kasai.manentiasoftware.com / Open Source Identity Management Solutions Written in Java http://www.manageability.org/blog/stuff/single-sign-on-in-java Spring Security ( aceig security ) http://static.springsource.org/spring-security/site /