DocumentCode
1576235
Title
Run-time enforcement model for Dynamic Separation of Duty
Author
Janpitak, Nanta ; Sathitwiriyawong, Chanboon
Author_Institution
Fac. of Inf. Technol., King Mongkut´´s Inst. of Technol. Ladkrabang, Bangkok, Thailand
fYear
2010
Firstpage
115
Lastpage
120
Abstract
Separation of duty (SoD) is a primary internal control in many businesses including information systems intended to prevent frauds and errors due to the conflict of interest. To enforce the separation of duty in the information systems, Role-Based Access Control (RBAC) has been proposed and been the most popular access control model in today´s security management. This paper focuses on the Dynamic Separation of Duty (DSD) which is one of the four components of the ANSI RBAC standard. To maximize the utilization of human resources, one user is allowed to have multiple mutually exclusive roles but can activate only one role at a time. The DSD does not only provide more flexibility for business system but also create more vulnerability in the separation of duty compliance because of the complication in checking the conflict of interest. This paper proposes a very simple but effective model to solve the problem of the DSD by integrating the workflow sequence to the concept of mutually exclusive roles (MER) constraint. From the proposed model, the conflict of interest can be verified at run time. The system will not allow the continuity of any process if the activation of conflicting users has been found.
Keywords
authorisation; information systems; ANSI RBAC standard; business system; dynamic separation of duty; fraud prevention; information systems; mutually exclusive roles constraint; role-based access control; run-time enforcement model; security management; ANSI standards; Access control; Business; Context; History; Information systems; Dynamic Separation of Duty (DSD); Mutually Exclusive Roles (MER); Role-Based Access Control (RBAC); Separation of duty (SoD); Static Separation of Duty (SSD); Workflow; the Constrained RBAC;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications and Information Technologies (ISCIT), 2010 International Symposium on
Conference_Location
Tokyo
Print_ISBN
978-1-4244-7007-5
Electronic_ISBN
978-1-4244-7009-9
Type
conf
DOI
10.1109/ISCIT.2010.5664902
Filename
5664902
Link To Document