• DocumentCode
    2721564
  • Title

    Obligations for Role Based Access Control

  • Author

    Zhao, Gansen ; Chadwick, David ; Otenko, Sassa

  • Author_Institution
    Comput. Lab., Univ. of Kent, Canterbury
  • Volume
    1
  • fYear
    2007
  • fDate
    21-23 May 2007
  • Firstpage
    424
  • Lastpage
    431
  • Abstract
    Role based access control has been widely researched in security critical systems. Conventional role based access control is a passive model, which makes authorization decisions on requests, and the authorization decisions contain only information about whether the corresponding requests are authorised or denied. One of the potential improvements for role based access control is the augmentation of obligations, where obligations are tasks and requirements to be fulfilled before, after or together with the enforcement of the authorization decisions. This paper conducts a literature review of role based access control and obligation related research, and proposes a design for the augmentation of obligations in the context of the RBAC standard. The design is then validated by implementation in the PERMIS RBAC authorization infrastructure. The paper also discusses the possible nondeterminism caused by overlapping authorisations.
  • Keywords
    authorisation; PERMIS RBAC authorization infrastructure; RBAC standard; authorization decisions; obligations; role based access control; security critical systems; ANSI standards; Access control; Authorization; Control system synthesis; Decision making; Information security; NIST; Permission; Scalability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications Workshops, 2007, AINAW '07. 21st International Conference on
  • Conference_Location
    Niagara Falls, Ont.
  • Print_ISBN
    978-0-7695-2847-2
  • Type

    conf

  • DOI
    10.1109/AINAW.2007.267
  • Filename
    4221096