• DocumentCode
    1175911
  • Title

    A generalized temporal role-based access control model

  • Author

    Joshi, James B.D. ; Bertino, Elisa ; Latif, Usman ; Ghafoor, Arif

  • Author_Institution
    Pittsburgh Univ., PA, USA
  • Volume
    17
  • Issue
    1
  • fYear
    2005
  • Firstpage
    4
  • Lastpage
    23
  • Abstract
    Role-based access control (RBAC) models have generated a great interest in the security community as a powerful and generalized approach to security management. In many practical scenarios, users may be restricted to assume roles only at predefined time periods. Furthermore, roles may only be invoked on prespecified intervals of time depending upon when certain actions are permitted. To capture such dynamic aspects of a role, a temporal RBAC (TRBAC) model has been recently proposed. However, the TRBAC model addresses the role enabling constraints only. In This work, we propose a generalized temporal role-based access control (GTRBAC) model capable of expressing a wider range of temporal constraints. In particular, the model allows expressing periodic as well as duration constraints on roles, user-role assignments, and role-permission assignments. In an interval, activation of a role can further be restricted as a result of numerous activation constraints including cardinality constraints and maximum active duration constraints. The GTRBAC model extends the syntactic structure of the TRBAC model and its event and trigger expressions subsume those of TRBAC. Furthermore, GTRBAC allows expressing role hierarchies and separation of duty (SoD) constraints for specifying fine-grained temporal semantics.
  • Keywords
    authorisation; computational linguistics; constraint handling; temporal logic; GTRBAC model; cardinality constraints; generalized temporal role-based access control; role-permission assignment; security management; separation of duty constraints; temporal constraints; temporal semantics; user-role assignment; Access control; Energy management; Permission; Power generation; Runtime; Security; 65; Index Terms- Access control; role hierarchy; role-based; separation of duty.; temporal constraints;
  • fLanguage
    English
  • Journal_Title
    Knowledge and Data Engineering, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1041-4347
  • Type

    jour

  • DOI
    10.1109/TKDE.2005.1
  • Filename
    1363762