DocumentCode :
2261790
Title :
A decentralized RBAC model and its user-role administration
Author :
Zhang, Xiantao ; Li, Qi ; Qing, Sihan ; Zhang, Huanguo ; Zhang, Liqiang
Author_Institution :
Wuhan Univ., Wuhan
fYear :
2007
fDate :
17-19 Oct. 2007
Firstpage :
1280
Lastpage :
1285
Abstract :
Role-based Access Control (RBAC) become an important techniques to secure e-commerce systems during recent years. However, RBAC management issue is still an unresolved problem. Moreover, with the development of IT technologies in many departments, there emerge many group communications which require dynamic user-role assignments. In these scenarios it is infeasible for few security officers to administrate the assignment for local variant applications. In this paper, we propose a novel RBAC model for decentralized and distributed systems. We also present an administration model of our RBAC model to address the management issues in traditional RBAC systems. As one of the main contributions, this paper proposes a decentralized administration model by introducing a component of group assignment to implement a novel user authorization mechanism and a new user-role assignment (UA) approach which provides a two-level administration for user and role management through the concept of group. Our model can be applied for the current group communication applications with dynamic assignments where typically local administrators take charge of the dynamic assignments. In this way, many administrative tasks for different applications can spread over many different local administrators, and a fine-grained administration model of RBAC based on the local administration policies is realized. As a proof-of-concept we implemented a prototype in Xen virtualization environment based on our proposed model to secure real distributed applications.
Keywords :
access control; authorisation; electronic commerce; multivariable systems; Xen virtualization; current group communication; decentralized RBAC model; distributed systems; dynamic assignments; e-commerce systems; fine-grained administration model; role-based access control; user authorization mechanism; user-role administration; Access control; Authorization; Communication system security; Computer science; Electronic mail; Environmental management; Information security; Software engineering; Videoconference; Virtual prototyping;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications and Information Technologies, 2007. ISCIT '07. International Symposium on
Conference_Location :
Sydney,. NSW
Print_ISBN :
978-1-4244-0976-1
Electronic_ISBN :
978-1-4244-0977-8
Type :
conf
DOI :
10.1109/ISCIT.2007.4392214
Filename :
4392214
Link To Document :
بازگشت