• DocumentCode
    241264
  • Title

    Permission based implementation of Dynamic Separation of Duty (DSD) in Role based Access Control (RBAC)

  • Author

    Habib, Muhammad Asif ; Mahmood, Nasir ; Shahid, Muhammad ; Umar Aftab, Muhammad ; Ahmad, Uzair ; Nadeem Faisal, C. Muhammad

  • Author_Institution
    Dept. of Comput. Sci., Nat. Textile Univ. (NTU), Faisalabad, Pakistan
  • fYear
    2014
  • fDate
    15-17 Dec. 2014
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    Role based Access Control (RBAC) is known as an evolution in the field of access control. The strength of RBAC is considered due to the incorporation of concept of roles. Separation of Duty (SOD) is a constraint that implements least privilege principle in RBAC. Dynamic Separation of Duty (DSD) is a powerful constraint to control internal security threats. Current RBAC standard implements DSD on the level of roles. This creates various problems. In this paper, various problems in case of implementing DSD on the level of roles are identified. We show and prove that RBAC´s strength is the incorporation of concept of roles but this is not for better security in terms of authorization. Instead this helps in better administration or usability for users. The RBAC usability can be improved if RBAC administration is being implemented on the basis of roles and access control can be more secure if DSD is being implemented on the basis of conflicting permissions. The concept of normalized roles is also introduced. The proposed model implements access control on the basis of normalized role. DSD is being implemented on the basis of conflicting permissions and non-conflicting permissions are exercised under the umbrella of role. This becomes a hybrid approach for access control. The administrators are given freedom in implementing DSD in various modes according to the organizational requirements from lenient to strict implementation. The proposed model is also formally specified and the benefits as a result of implementing the proposed model are discussed.
  • Keywords
    authorisation; DSD; RBAC administration; RBAC standard; RBAC usability; SOD; authorization; dynamic separation of duty; internal security threats; organizational requirements; permission based implementation; role based access control; Authorization; Business; Permission; Standards; Usability; DSD; RBAC; SOD;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Signal Processing and Communication Systems (ICSPCS), 2014 8th International Conference on
  • Conference_Location
    Gold Coast, QLD
  • Type

    conf

  • DOI
    10.1109/ICSPCS.2014.7021054
  • Filename
    7021054