DocumentCode
2721564
Title
Obligations for Role Based Access Control
Author
Zhao, Gansen ; Chadwick, David ; Otenko, Sassa
Author_Institution
Comput. Lab., Univ. of Kent, Canterbury
Volume
1
fYear
2007
fDate
21-23 May 2007
Firstpage
424
Lastpage
431
Abstract
Role based access control has been widely researched in security critical systems. Conventional role based access control is a passive model, which makes authorization decisions on requests, and the authorization decisions contain only information about whether the corresponding requests are authorised or denied. One of the potential improvements for role based access control is the augmentation of obligations, where obligations are tasks and requirements to be fulfilled before, after or together with the enforcement of the authorization decisions. This paper conducts a literature review of role based access control and obligation related research, and proposes a design for the augmentation of obligations in the context of the RBAC standard. The design is then validated by implementation in the PERMIS RBAC authorization infrastructure. The paper also discusses the possible nondeterminism caused by overlapping authorisations.
Keywords
authorisation; PERMIS RBAC authorization infrastructure; RBAC standard; authorization decisions; obligations; role based access control; security critical systems; ANSI standards; Access control; Authorization; Control system synthesis; Decision making; Information security; NIST; Permission; Scalability;
fLanguage
English
Publisher
ieee
Conference_Titel
Advanced Information Networking and Applications Workshops, 2007, AINAW '07. 21st International Conference on
Conference_Location
Niagara Falls, Ont.
Print_ISBN
978-0-7695-2847-2
Type
conf
DOI
10.1109/AINAW.2007.267
Filename
4221096
Link To Document