在基于角色的访问控制模型的基础上引入了任务(task)和任务实例(task instance) 的概念,建立了基于角色和任务的访问控制模型(R&TBAC),给出了形式化定义,并且对该模型进行了安全性分析,结果表明R&TBAC 模型支持两个著名的安全原则:职责分离原则和最小特权原则,并具有很好的动态适应性。 关键词:模型;访问控制;角色;任务 Abstract:Introduce the concept of task and task instance into role-based access control model, build the role & task – based access control model, propose its formal definition. The security of the model is analyzed, the result show that role & task –based access control model supports two security principles such as least privilege and separation of duty, and has good dynamic adoption. Key works:model; access control; role; task