DocumentCode
1991183
Title
A formal model for flat role-based access control
Author
Khayat, E.J. ; Abdallah, A.E.
Author_Institution
Centre for Appl. Formal Methods, London South Bank Univ., London, UK
fYear
2003
fDate
14-18 July 2003
Firstpage
75
Abstract
Summary form only given. Role-based access control (RBAC) is very useful for providing a high level description of access control. It enables a better understanding of the security problems in an institution because it bridges the gap between their technical aspects and their managerial descriptions. Several models have been devised to describe RBAC. However, the definitions of some of the concepts of RBAC, such as subject, role and permission, were open to many interpretations. Also, the devised models for RBAC, did not detail the analysis of the access operations in RBAC. We formalize each of the basic concepts of RBAC for their definitions to be clear and precise. Based on these definitions, a formal state-based model for flat role based access control (FRBAC) is constructed and described in the specification notation Z. This approach permits the close examination of the states in the system. Consequently, it helps to analyse in depth the access operations of RBAC. The model is also refined by supporting the concepts of active roles and private permissions. In the future, the model can be enhanced by extending it to model the delegation and revocation of roles. Other developments of this model include the support of the separation of duty constraints.
Keywords
authorisation; formal specification; specification languages; FRBAC; Z specification notation; authorisation; duty constraint separation; flat role-based access control; formal state-based model; private permissions; security problems; Access control; Authorization; Bridges; Permission; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Systems and Applications, 2003. Book of Abstracts. ACS/IEEE International Conference on
Conference_Location
Tunis, Tunisia
Print_ISBN
0-7803-7983-7
Type
conf
DOI
10.1109/AICCSA.2003.1227507
Filename
1227507
Link To Document