• DocumentCode
    2358815
  • Title

    Multi-session Separation of Duties (MSoD) for RBAC

  • Author

    Chadwick, David W. ; Xu, Wensheng ; Otenko, Sassa ; Laborde, Romain ; Nasser, Bassem

  • Author_Institution
    Univ. of Kent, Canterbury
  • fYear
    2007
  • fDate
    17-20 April 2007
  • Firstpage
    744
  • Lastpage
    753
  • Abstract
    Separation of duties (SoD) is a key security requirement for many business and information systems. Role based access controls (RBAC) is a relatively new paradigm for protecting information systems. In the ANSI standard RBAC model both static and dynamic SoD are defined. However, static SoD policies assume that the system has full control over the assignment of all roles to users, whilst dynamic SoD policies assume that conflicts of interest can only arise during the simultaneous activation of a user´s roles. Unfortunately neither of these assumptions hold true in dynamic virtual organisations (VOs), or in business processes that span multiple user sessions, or where users only partially disclose their roles at each session. In this paper we propose multi-session SoD (MSoD) policies for business processes which include multiple tasks enacted by multiple users over many user access control sessions. We explore the means to define MSoD policies in RBAC via multi-session mutually exclusive roles (MMER) and multi-session mutually exclusive privileges (MMEP). We propose an approach to expressing MSoD policies in XML and enforcing MSoD policies in a policy controlled RBAC infrastructure. Finally, we describe how we have implemented MSoD policies in the PERMIS privilege management infrastructure.
  • Keywords
    authorisation; virtual enterprises; ANSI standard; RBAC; XML; information system security; multiple user sessions; multisession mutually exclusive privileges; multisession mutually exclusive roles; multisession separation of duties; role based access controls; virtual organisations; ANSI standards; Access control; Accidents; Control systems; History; Information security; Information systems; Management information systems; Protection; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Data Engineering Workshop, 2007 IEEE 23rd International Conference on
  • Conference_Location
    Istanbul
  • Print_ISBN
    978-1-4244-0832-0
  • Electronic_ISBN
    978-1-4244-0832-0
  • Type

    conf

  • DOI
    10.1109/ICDEW.2007.4401062
  • Filename
    4401062