<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>[1] D. Ferraiolo, J. Cugini, R. Kuhn. Role-based access control: Features and motivations. In Proceedings of Annual Computer Security Applications Conference, IEEE Computer Society Press</institution>
          ,
          <addr-line>1995, pp. 249 255</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>[2] D.F. Ferraiolo, D.R. Kuhn. Role-Based Access Controls. In Proceedings of 15th National Computer Security Conference</institution>
          ,
          <addr-line>Baltimore MD, 1992, pp. 554 563</addr-line>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>[3] M. Nyanchama, S.L. Osborn. Access Rights Administration inRole-Based Security Systems. In Proceedings of the IFIP WG11.3 Working Conference on Database Security VII</institution>
          ,
          <addr-line>North-Holland, 1994, pp. 37 56</addr-line>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>[4] R. Sandhu, E. Coyne, H. Feinstein, C. Youman. Role Based Access Control: A multidimensional view. In Proceedings of 10th Annual Computer Security Applications Conference</institution>
          ,
          <addr-line>Orlando, 1994, pp. 54 62</addr-line>
        </aff>
        <aff id="aff4">
          <label>4</label>
          <institution>[5] R.S. Sandhu, E.J. Coyne, H.L. Feinstein, C.E. Youman. Role-Based Access Control Models. IEEE Computer</institution>
          ,
          <addr-line>1996, N. 29(2), pp. 38 47</addr-line>
        </aff>
      </contrib-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Ø</p>
      <p>Æ
Ł
Ł Ł
ß ae
Ł
ßŒ</p>
      <p>Æ
ºŁ RBAC2
Ł
Ł</p>
      <p>ª
ª Ł
Ł
XMLŁ
ŁÆ º
ŁaeŒº
Ł ı ÆŁ
ł Ł . ´
Ł Ł
Ł</p>
      <p>ae
øŁ</p>
      <p>ºŁ¿.
ßı ł</p>
      <p>ae ae Ł,
ª ł
ŁaeŒº øŁ
ßŒ GraphML.
Æ ßØ
ŁØ.</p>
      <p>aeŁØ.</p>
      <p>Æ
aeŁae
Ł
Ł ,
Æ
ª º Ł</p>
      <p>Ł ae Øae
ŁØ Œ aeŁae , Œ</p>
      <p>ºŁ RBAC0 Ł Œ
º ª ß
ª Ł Ł
Ł
ª Æß</p>
      <p>ºŁ
º , Œ Ł aeº
º Ø RBAC 1 Ł RBAC2 Ł,
ß Ł Łae</p>
      <p>(Role Base Access Control,
ßı º Ø. º RBAC0</p>
      <p>Ł º
Ł Ł ıŁŁ º Ø. RBAC 2
ß Œ ß ºŁ. ˝
ßı º Ø Ł</p>
      <p>Ł Ł
Ł ß ºŁ,
ß
º ,
ae
ª Ł Ł
ae Ł Æ Ł</p>
      <p>Ł , Ł ŁaeŒº
. . RBAC3 Æoe Ł
ae Ł, ºŁ RBAC0. ˚
Ł Ł Œ ae Ł
´ Æ</p>
      <p>Ł aeŒ Ø ºŁ
Æ ı [1, 2, 4, 5]. ˇ Ł
oe º ø Ł Ł
. RBAC1 Œº</p>
      <p>ºŁ RBAC 0 Ł ª
øŁ ºŁ, Œ ºŁ ae
ø º , Œº
Æß ßı º Ø
Ł aeŁae ae Ł</p>
      <p>aeae Ł
Łae
Ø Æ ae
Ł ŁaeŒº øŁ ºŁ¿. ˝ Ł ae
(Enterprise Resource Planning Systems, ERP-aeŁae
Œ ı RBAC- ºŁ º Ł ae º
Ø
ŁÆ º
ı)
øŁ</p>
      <p>ae
ßı aeŁae</p>
      <p>Ł
ºŁ
ŁŁ Œ
Ø [3].</p>
      <p>ae
ı
Ł
ŁŁ
ŁaeŒº
º Ł
º Ł
øŁı
Ł Ł
ae ae Ł</p>
      <p>º Ø</p>
      <p>ºŁ RBAC2
Ł Ł
`Ł</p>
      <p>Ł
2. ˝
˜º
Ł
Ł
Ø aeŁae
º Ø
Łae
º Ø R,</p>
      <p>Ł
º Ø Ł</p>
      <p>aeŁae
ºŁ RBAC 0
ºŁ RBAC2
ß.</p>
      <p>Æı</p>
      <p>Ł
ŁØ P ,
ae ae
1. ´ß
º Ł
Ł Łı</p>
      <p>ŁØ.
º Ł
Ł Ł
ı
ºŁ
º Ø U .
Æ
Ł :
˛ Æ
˛ Æ
Ł
ºŁ
U R : U
º
Æß
Œ
Ł
ºŁ r ae
º
º Ø u:r</p>
      <p>ae
Ł
R,</p>
      <p>Fsession roles : U
Ł ºŁ º
! 2R, Œ</p>
      <p>º
øŁ
! 2R, Œ
ºŁ
ºŁ¿ Œ Œ</p>
      <p>Œ
ae Ł
ae
ae
º
ae
Æ
ß
¿ ae
,
ae Ł Ł</p>
      <p>ŁŒ ŒŁ
u:sr.
º
ª</p>
      <p>ŒaeŁ º
aeº
ª</p>
      <p>ae
Œ ae
ª</p>
      <p>łŁ
O(n2 2n).</p>
      <p>ŁaeŁ
Æ
ß
ı
ae
ae
Łae º
ae ae
ª
º
Œ ae
º</p>
      <p>ŁØ.
Æ
ı
ł Ł
ae ae Ł
ª G= Łae
Æ ß ae ae Æ
. ˇ ae jRj = n.</p>
      <p>º ae Łº :
˛ Ø Ł
Ł º</p>
      <p>ae ae Ł,
ae ae Ł,
ł ae</p>
      <p>ø
Ł ŁaeŒº
Æoe Œ Ł</p>
      <p>º
º
º</p>
      <p>Œ
ºŁ Œ
Ł
ßı
Ł
Ø Ł
º
aeae
Ł
Ł Ł ae
ae Ł ª , ae
ae ae
ae
ˇŁ 1. ˇ ae º Ł r1, r2 Ł r3
r2:p = fp3; p4g Ł r3:p = fp1; p3; p4g. ¨ ae</p>
      <p>Ł ŁØ Æ ae ae Ł aeŁae ß. — aeae Ł
Ł Æ u:r = fr1; r2; r3g. ª ae
ae º ß aeº øŁ Æ</p>
      <p>ŁØ fp1; p2; p3; p4g ae Ł
º u, Œ ßØ Æß
ß ae aeŁae Ø º º u
: r1:p = fp1; p2g,</p>
      <p>ae Ł ß ae
Ł ºŁ
,
Ł ß</p>
      <p>ł Ł
ß (r3; r1) Ł
ˇŁ 2.</p>
      <p>SQL Server º
ae Æ</p>
      <p>˝
º
ae
º
fr6; r7g. ª
Łae Œ
ae
( º
Æß</p>
      <p>1
º Ł
ae
ae
ŁØ). ˜º
º
ß ae
Œ
Æ ae
ae
aeº
ß
ºŁ Ł
, r4
ß.
Ł ŁaeŒº
. ˇ
ß, Łaeı
2). ´
º Ł ª</p>
      <p>º Ø.
Œ Ł Ł
ŁŒº</p>
      <p>ß Ł
º
aeº
,
Ł</p>
      <p>The Mutual Exclusion Relation on a Set of Roles in Access Control Models</p>
      <p>Nadezda F. Bogachenko</p>
      <p>The most widespread restriction of the RBAC 2 model is the "mutually exclusive roles". This restriction
is interpreted in terms of the binary relations. Properties of the constructed relation are studied. In particular,
transitive and intransitive relations are considered. The XML-like GraphML language is o ered to use as language
of the description of restriction "mutually exclusive roles".</p>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>