Configuring role-based access control to enforce mandatory and discretionary access control policies

Author:

Osborn Sylvia1,Sandhu Ravi2,Munawer Qamar2

Affiliation:

1. Univ. of Western Ontario, London, Ont., Canada

2. George Mason Univ., Fairfax, VA

Abstract

Access control models have traditionally included mandatory access control (or lattice-based access control) and discretionary access control. Subsequently, role-based access control has been introduced, along with claims that its mechanisms are general enough to simulate the traditional methods. In this paper we provide systematic constructions for various common forms of both of the traditional access control paradigms using the role-based access control (RBAC) models of Sandhu et al., commonly called RBAC96. We see that all of the features of the RBAC96 model are required, and that although for the manatory access control simulation, only one administrative role needs to be assumed, for the discretionary access control simulations, a complex set of administrative roles is required.

Publisher

Association for Computing Machinery (ACM)

Subject

Safety, Risk, Reliability and Quality,General Computer Science

Cited by 259 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Assessment of energy consumption for information flow control protocols in IoT devices;Internet of Things;2023-12

2. A Survey of Blockchain-Based Schemes for Data Sharing and Exchange;IEEE Transactions on Big Data;2023-12

3. Provisioning trust-oriented role-based access control for maintaining data integrity in cloud;International Journal of System Assurance Engineering and Management;2023-09-09

4. MS-UCON: A Usage Control Model for Meteorological Operational Systems;2023 19th International Conference on Natural Computation, Fuzzy Systems and Knowledge Discovery (ICNC-FSKD);2023-07-29

5. A Robust Approach for the Detection and Prevention of Conflicts in I2NSF Security Policies;NOMS 2023-2023 IEEE/IFIP Network Operations and Management Symposium;2023-05-08

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3